Orchestrator Policy Documentation - Commands

Command

Purpose

Typical Use Case

cmd_4F_CP

Four-Fingers biometric authentication through Credential Provider

Windows logon/unlock with Veridium 4F biometrics

cmd_4f_mobile

Four-Fingers biometric authentication on mobile

Mobile passwordless authentication

cmd_LDAP_password

LDAP password challenge

Browser-based authentication against AD/LDAP

cmd_LDAP_password_desktop

LDAP password challenge from Credential Provider/Desktop

Windows authentication using directory password

cmd_QR

QR code authentication dispatch

Cross-device authentication (scan QR with mobile app)

cmd_authentication_context_awareness

Execute Context Awareness engine

Risk-based authentication decisions

cmd_certificate

Certificate-based authentication

Smart card, client certificate, PKI authentication

cmd_certificate_mobile

Certificate authentication using mobile security key/certificate

Mobile certificate workflows

cmd_delegate_authentication

Delegate authentication to another authenticator or workflow

Shared accounts, delegated approvals

cmd_desktop_fingerprint

Fingerprint authentication on desktop

Desktop biometric login

cmd_external_pin_browser

PIN verification outside browser session

Browser authentication requiring external PIN validation

cmd_fido_browser

FIDO/FIDO2 authentication in browser

Security key or passkey login

cmd_lost_mode_browser

Lost Mode workflow for browser sessions

Device recovery / account recovery

cmd_lost_mode_only

Force Lost Mode workflow

Dedicated recovery journey

cmd_native_biometrics_mobile

Native mobile biometrics (FaceID, TouchID, Android Biometrics)

Mobile passwordless authentication

cmd_otp

One-Time Password challenge

Generic OTP authentication

cmd_otp_only

OTP-only authentication flow

Environments where OTP is the sole factor

cmd_pin_browser

Browser PIN challenge

PIN authentication from browser

cmd_pin_mobile

Mobile PIN challenge

PIN authentication within mobile app

cmd_push

Push notification authentication

Standard Veridium push approval

cmd_push_with_userpresence_code

Push approval plus user-presence verification code

Higher assurance push authentication

cmd_qr_offline

Offline QR authentication

Authentication without network connectivity

cmd_sms_browser

SMS OTP for browser sessions

Browser MFA using SMS

cmd_sms_only

SMS-only verification

Recovery or low-assurance MFA

cmd_totp_browser

TOTP authentication in browser

Google Authenticator / Microsoft Authenticator style MFA

cmd_totp_desktop

TOTP authentication initiated by Veridium Desktop Authenticator

Desktop MFA workflow

cmd_uba_context

Execute UBA Context analysis

Behavioral risk scoring

cmd_uba_motion

Execute UBA Motion analysis

Device motion and behavior analysis

cmd_vface_browser

Veridium Face Authentication in browser

Browser-based face biometric challenge

cmd_vface_mobile

Veridium Face Authentication on mobile

Mobile face biometric challenge

cmd_wbf

Windows Biometric Framework authentication

Windows Hello / native biometric integration

cmd_yubico_otp

Yubico OTP authentication

YubiKey OTP challenge


Functional Grouping

Biometric Commands

  • cmd_4F_CP

  • cmd_4f_mobile

  • cmd_desktop_fingerprint

  • cmd_native_biometrics_mobile

  • cmd_vface_browser

  • cmd_vface_mobile

  • cmd_wbf

Password / PIN Commands

  • cmd_LDAP_password

  • cmd_LDAP_password_desktop

  • cmd_external_pin_browser

  • cmd_pin_browser

  • cmd_pin_mobile

OTP Commands

  • cmd_otp

  • cmd_otp_only

  • cmd_sms_browser

  • cmd_sms_only

  • cmd_totp_browser

  • cmd_totp_desktop

  • cmd_yubico_otp

Push / QR Commands

  • cmd_push

  • cmd_push_with_userpresence_code

  • cmd_QR

  • cmd_qr_offline

Certificate / FIDO Commands

  • cmd_certificate

  • cmd_certificate_mobile

  • cmd_fido_browser

Risk Analysis Commands

  • cmd_authentication_context_awareness

  • cmd_uba_context

  • cmd_uba_motion

Recovery / Special Purpose Commands

  • cmd_delegate_authentication

  • cmd_lost_mode_browser

  • cmd_lost_mode_only

Last updated: