Restrict Available Predefined Offline Temporary Password Durations

Which aspect of EPP are you submitting for?

Endpoint Protector Server

What is a one sentence summary of your feature request?

Allow administrators to enable or disable predefined Offline Temporary Password duration options based on administrator role.

Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.

Endpoint Protector currently provides a fixed list of predefined Offline Temporary Password durations that are available to administrators generating OTPs.

Many organisations have internal security policies that limit the maximum duration for temporary offline access. While administrators can choose the Custom option, the predefined durations still present options that may exceed an organisation’s policy.

We would like the ability to control which predefined duration options are available to administrators.

For example, an organisation may wish to allow only:

15 minutes
30 minutes
1 hour
4 hours
8 hours
24 hours

while hiding options such as:

2 days
3 days
5 days
7 days

This would help ensure administrators can only select durations that comply with the organisation’s security policy.

Ideally, this should be configurable on an administrative role basis rather than as a single global setting.

For example, administrators assigned the Offline Temporary Password Administrator role could have restricted duration options, while Super Administrators retain access to all predefined durations for exceptional circumstances.

This provides greater flexibility while still allowing organisations to enforce their day-to-day operational policies.

How do you currently solve the challenges you have by not having this feature?

Currently this can only be addressed through documentation, training and internal procedures.

There is nothing to prevent an administrator from selecting a predefined duration that exceeds the organisation’s policy.

Being able to restrict the available predefined durations would allow organisations to enforce their policy within the product rather than relying on manual processes.

1 Like

Hi Jeremy,

Thank you — this is also a well-reasoned request. The use case around policy enforcement I’d say is clear. Being able to restrict available durations by role is a meaningful control gap for organisations with strict temporary access policies.

As I mentioned in a an earlier answer, we do have OTP-related improvements on the way and we’ll keep this request in view as that work evolves. That said, this particular enhancement is more involved than a configuration change. It touches role-based permissions and how the OTP generation flow is presented to different admin types so it’s unlikely to be included in the near-term work. It’ll need its own evaluation once the foundational changes are out.

We’ve logged it and will revisit it in that context. No timeline to share yet, but it’s noted.

2 Likes