Create authentication flows

An authentication flow determines how a user authenticates. IDaaS supports the following authentication flows:

       User LoginThe user enters their user ID and is prompted to authenticate using any of the IDaaS authenticators.

       Smart Login—The user interacts with an Entrust Identity Smart Credential to authenticate. The user does not enter their userID because authentication involves a passwordless authentication flow. The user ID is obtained from the Smart Credential.

Smart Login is available only if the account has been enabled to allow Smart Login. Smart Login can be used to authenticate to the Identity as a Service Admin Portal, User Portal, OIDC, and SAML applications integrated with Identity as a Service.

Note: Entrust recommends that User Login flow should also be enabled when Smart Login is selected in an authentication flow.

       Passkey—The user authenticates with a FIDO2/Passkey token. The user does not enter their user ID because authentication involves a passwordless authentication flow. The user ID is obtained from the FIDO2/Passkey token.

       Identity Provider—The user is forwarded to an external SAML or OIDC Identity Provider to authenticate. The user ID is provided by the Identity Provider.

       User Certificate—The user authenticates with a user certificate. The user does not enter their user ID because authentication involves a passwordless authentication flow. The user ID is obtained from the user certificate.

When you create a resource rule, you need to select an authentication flow for the rule. You can select to use a system authentication flow or create a custom flow. IDaaS has the following pre-configured System Authentication Flows:

       Access Denied

       Default Second Factor Only

       Domain-based IDP Only

       Entrust Soft Token Push, Software/Hardware Token, One Time Password

       External and Second Factor

       External Only

       Passkey Only

       Password and Second Factor

       Password and Software/Hardware Token

       Password and Software/Hardware Token, Temporary Access Code

       Password Only

       Smart Login Only

       Software/hardware Token and Temporary Access Code

       Software/Hardware Token Only

       User Certificate Only

Manage Authentication Flows

View authentication flows

Clone an authentication flow

Create a custom authentication flow

Edit an authentication flow

Delete an authentication flow