Getting started with Adaptive Authentication for Trusted Mobile Apps
In this video, we show administrators how to activate Adaptive Authentication for Trusted Mobile Apps, and show users how to register their devices. With Adaptive Authentication for Trusted Mobile Apps, users can access the Now mobile app from outside your network on trusted devices. Let’s follow along as Shaun, our administrator, activates Adaptive Authentication for Trusted Mobile Apps on our instance. First, we need to install the Adaptive Authentication plugin. Next, we need to access the Adaptive Authentication properties page. Here we enable the authentication policy and device trust flow properties. Now we’re ready to define the pre-authentication conditions. We navigate to Pre-Authentication Contexts, and select the Default policy, which can be either Allow or Deny. Deny is the default for this choice. These policies are direct opposites. With the Allow policy, all users are denied access by default, and it only allows access when the allow access policy conditions are true. With the Deny policy, all users are allowed access by default, and it only denies access when the
deny access policy conditions are true. In our example, we select the Allow policy because we want to define a set range of trusted IP addresses that users can login from to access our instance. Now we’ll open the Allow policy, here, to define our policy inputs. We want to give users access based on their trusted IP address or if they have a registered device, so we select these options and move them to the Policy Inputs List. Let’s configure our range of trusted IP addresses. The Trusted Mobile App option requires no configuration, so now we can set up our policy conditions. We add a label and start building out our conditions. We select Trusted IP Range is true, … … or Trusted Mobile App is true. So, if a user accesses a network inside our trusted IP Range, or outside our trusted IP Range from a registered mobile app, they’ll be allowed access. Now our users can start registering their devices. Let’s follow along as Adela, a traveling auditor, registers her mobile device so she can access the Now mobile app on the road. We access our instance from our trusted network
and click our username in the instance header. Then we open our profile, … …click the Register Trusted Device link, … …and add a new trusted device. Now we’re shown a QR code to scan from within
the Now mobile app on our mobile device. Let’s switch to our mobile device, where
the Now mobile app is installed and open. When we tap on our instance name to log in, we’re presented with the Device Registration page. Now we scan the QR code on the instance with our device, to pair them. With our device registered, we can now log in to the mobile app. When the device is registered, it’s displayed
on the Register Trusted Devices page. If we need to remove the registered device
later, we can select the delete icon here. Note that admins can remove registered
devices from any user’s account. So the next time Adela needs to access the Now Mobile app, she can access it from any network, anywhere. For more information, see our product documentation or knowledge base. Or ask a question in the ServiceNow Community.
https://www.youtube.com/watch?v=rIQNf4M7LyU