Ivanti Neurons Authentication

As an Ivanti Neurons customer you can choose how your members are to authenticate with the Ivanti Neurons Platform. By default a new tenant is configured for username and password authentication.

On initial sign up to the Ivanti Neurons Platform, once you have accepted the End User License Agreement, you are presented with the option to increase the security of your tenant by enabling an additional authentication method. You have the option to do it immediately, or at a later date. Once selected to Do It Now, the Authentication page provides you with two methods to choose from; External Authentication (SSO) and Ivanti Neurons Multi-Factor Authentication (MFA). See the relevant section for details on how to proceed with your preferred method.

External Authentication (SSO) and Ivanti Neurons Multi-Factor Authentication (MFA) are mutually exclusive. If you are using an external authentication provider, you should leverage the MFA provided by that solution.

External Authentication (SSO)

Leverage single sign-on (SSO) which offers enhanced control over account security and policies, and alignment with other applications in use, such as Office 365, which makes for a more consistent user experience.

You currently have the option of selecting Entra ID as the external authentication provider. This is a good choice if you want to centralize the end user log on experience, reduce the occurrence of password related calls to the help desk, and have granular controls over policies and audit trails. Multi-Factor Authentication can be used when provided by Entra ID.

Ivanti Neurons Multi-Factor Authentication (MFA)

If you cannot use Entra ID authentication we recommend leveraging Ivanti Neurons Multi-Factor Authentication (MFA) to improve the security of the initial username and password based authentication, this gives an extra layer of protection by requiring an end user to use a security authenticator app on a mobile device to authenticate with the platform.

Session Timeout

To add a further level of security, the Ivanti Neurons session is configured to time out after 30 minutes of inactivity. The timeout period can be increased or decreased.

  1. Navigate to Admin > Authentication.
  2. In the Session Timeout section, select Configure.
  3. From the Session Timeout drop-down, select the required period of inactivity after which a user will automatically be logged out.
    You can select in increments of minutes: 5, 15, 30, or 60, or hours: 4 or 8.
  4. Anything more than 30 minutes is not recommended as it lowers the level of security.

Session Limit

To improve security, the administrator can configure the number of Ivanti Neurons concurrent sessions per user.

To configure session limit, follow these steps:

  1. Navigate to Admin > Authentication.

  2. In the Session Limit section, select Configure.
    By default, the concurrent Session Limit is set to Off, and allows any number of concurrent sessions.

  3. From the Session limit dropdown list, select the number of concurrent sessions you allow per user. You can select Off or a value from 1 to 10.

    When the session limit is reached and the user attempts to start another session, the page displays a list of all existing concurrent sessions. The user can choose to terminate any session from the list to continue with the new session, or cancel the new request and return to any existing session.

Login Banner

Configure a custom login banner to display important information to users before they login. This helps communicate key messages, such as acceptable use policies, security reminders, or other organizational information, at the start of a session.

By default, no login banner is displayed. You can enable, modify, or remove the login banner from the login banner section in Authentication.

To configure the login banner, follow these steps:

  1. Navigate to Admin > Authentication.

  2. In the Login Banner section, select Configure & Enable.
    The Configure Login Banner page appears.

  3. Enter a Title and Banner Text.

    Alternatively, click Disable & Delete to remove the content and turn off the login banner. Or, click Cancel to revert any changes.

    The fields marked with an asterisk (*) are mandatory.

  4. On the Confirm Save & Enable pop-up, click Save & Enable. Or, click Cancel to discard the changes.

Once the changes are saved successfully, the login banner is displayed to all users before they log in. Users must select Continue to proceed.

To edit or disable the login banner, click Edit or Disable under the Login Banner section. Or, you can cancel the changes based on your requirement.

The Edit or Disable under the Login Banner section only if the login banner is active.

Related topics

External Authentication (SSO)

Ivanti Neurons Multi-Factor Authentication (MFA)