Chapter 3: Active Directory Management
Assigning tokens to users
50
Note:
The same sequence of passcodes is generated every time you press the
Generate
button until one of them is successfully used for authentication.
4
Under Emergency Passcodes, click the
Generate
button. SafeWord 2008
automatically generates the number of passcodes you request, and they
appear in the order in which they must be used.
5
Inform the user of the emergency passcodes.
Important: Emergency passcodes must be used in the same sequential order in
which they were generated. Emergency passcodes are exactly like token-
generated one-time passcodes, and cannot be used more than once.
Reassigning Hardware and Messaging tokens
When users leave your organization or no longer need to authenticate with
SafeWord 2008, their SafeWord token and its records can be reassigned to
another user. You reassign Hardware tokens by removing the token serial
number from the departing user’s properties, then adding that serial number to
the new user’s properties and giving the token to the new user. Removing a
serial number disassociates the token records from the user. It does not
remove that information from your database. When you assign the token serial
number to a new user, a new association is created. Once the token is given to
the new user, that user can generate passcodes for authentication to access
your protected resources.
Important: When a token is lost, stolen, or broken you must completely remove the
token records from your database (as token records are obsolete without the
token). See “Deleting token records from the database” on page 51 for information
about deleting token records.
When Software or Messaging tokens are unassigned, they are placed back in
the pool of available tokens, and can be assigned to another user.
Note:
For Messaging tokens, remove the Messaging token from the user
properties, and assign a new Messaging token using the Wizard.
To reassign a token, do the following:
1
In ADUC, select the
Users
folder in the left pane.
2
Locate the user, right-click on the user name
for whom you are
disassociating token records, then select
Properties
.
3
Select the
SafeWord
tab in the user’s Properties window.
4
Clear the serial number from the
Token serial number
field, and then click
the
Apply
button.