User Administration > User authentication > Fingerprint authentication
  

Fingerprint authentication

Fingerprint authentication verifies that a Secure Agent starts up on the same machine it was set up on. You can configure settings to customize how your organization handles fingerprint mismatches.
The first time an agent starts up, IDMC uses anonymized device attributes to create a unqiue fingerprint of the Secure Agent machine. Every subsequent time that the agent starts up, IDMC checks the fingerprint and, if there's a mismatch, sends an alert to the notifications tray for administrators.
Note:
If you uninstall and reinstall the Secure Agent on the same machine, the fingerprint remains the same.
Configure settings for fingerprint authentication in the Authentication section of the Settings page. The following table describes the fingerprint authentication properties:
Property
Description
Fingerprint Enforcement
Prevents the Secure Agent from starting up and logs an error when there's a fingerprint mismatch.
IDMC logs the following error in the agentcore.log file:
Internal error. Agent <Secure Agent ID> fingerprint is not matching with the previous stored value for request <request ID>.
When you disable this property and there's a fingerprint mismatch, the Secure Agent starts up normally. Default is off.
Fingerprint Mismatch Email Notifications
To receive mismatch alerts by email, enter an email address.
IDMC checks the email format, but doesn't verify the email address. Be sure to allow emails from the address "admin@informaticacloud.com".
IDMC sends an email with the following message:
There was a fingerprint mismatch while logging in agent with name <Secure Agent name> for Organization <organization ID>. The agent was last active on <date in UTC>.