Selectors
|
Selector |
Purpose |
Routing logic |
Typical use case |
|---|---|---|---|
|
ILP_Selector |
Starts authentication through ILP_journey |
Always routes to |
Use when login must go through the ILP flow |
|
NoPhone_Selector |
Starts authentication through No_Phone_Journey |
Always routes to |
Users without phone-based authenticators |
|
Delegated_Authentication |
Chooses delegated authentication for shared accounts |
|
Shared/delegated account access |
|
Specific_Groups_Selector |
Routes selected groups to stronger authentication |
|
Group-based MFA enforcement |
|
CBA_Selector |
Enables certificate-based authentication entry options |
Always routes to |
Certificate-based authentication scenarios |
|
selector_default |
Default selector |
Always routes to |
Baseline/default authentication |
|
Windows_Login |
Credential Provider selector based on group assignment |
|
Windows logon requiring LDAP + second factor for selected groups |
Journey Highlevel
|
Journey |
Purpose |
Flow |
Typical use case |
|---|---|---|---|
|
journey_default |
Default single-challenge journey where the user chooses from available authenticators |
|
Standard login flow |
|
ILP_journey |
Authentication with ILP / UBA validation, followed by PIN step-up if risk fails |
|
Risk-based login with fallback step-up |
|
No_Phone_Journey |
Authenticate users without relying on phone-based methods |
|
Users without mobile app or phone access |
|
Two_factor_auth |
Two-step authentication journey |
|
Enforce two independent factors |
|
Delegate_Authentication |
Delegated/shared-account authentication workflow |
|
Shared account or delegated approval scenarios |
|
CP_2factor_with_LDAP |
Credential Provider two-factor flow with LDAP password as second factor |
|
Windows login requiring Veridium factor plus LDAP password |
Journey details
|
Journey |
Challenge nodes |
Commands used |
|---|---|---|
|
journey_default |
|
|
|
ILP_journey |
|
|
|
No_Phone_Journey |
|
|
|
Two_factor_auth |
|
First: |
|
Delegate_Authentication |
|
First: |
|
CP_2factor_with_LDAP |
|
First: |