Skip to main content
Skip table of contents

Creating and Configuring a Credential Policy

Credential types enable organizations to map users to specific certificates and card policies within the CMS. Additionally, organizations can specify qualification rules to ensure users meet certain business rules before they can be assigned to a specific credential type.

The feature is useful if the organization wants to segment different users for different types of credentials. For example, users within a general access group may receive credentials with low assurance certificates whereas users within an administrator group could receive high assurance certificates.


Prerequisites

  • Before assigning a credential type, a card policy must exist within the CMS.

  • There is a one-to-one relationship between the IDMS credential type and the CMS card policy. Therefore, the IDMS credential types cannot share CMS card policies.

  • System Administrator role required. Role Definitions


Creating a New Credential Policy

The steps below provide the procedure for creating a new credential policy:

Item

Procedure

Example

1

Go to Administration, and then click on the Credential Types button.

image-20260521-181527.png

2

When the Credential Policy Management window appears, press + Credential Policy to add a new policy.

image-20260521-182056.png

3

Enter the following information:

  • Credential Policy Name: Enter the Name of the policy.

  • Credential Policy Description: Description of the purpose of the credential policy.

  • Credential Policy Key: Enter a 5-character abbreviation of the credential policy.

image-20260521-182346.png

4

Select the Add button to add the new policy.

Then, you can configure the policy using the following settings in the table below.

Once you setup the new credential policy, then you can configure the policy using the following settings listed in the tables below.


Configuring the New Credential Policy

The following settings allow for customization of the credential policy to meet organizational security and management needs.

Item

Description

Example

Navigation to Access Configuration

To configure an existing policy:

  • Click Administration and select Credential Types.

  • Select a Credential Policy and press the corresponding gear button. Press Configure Policy.

  • Navigate across the different tabs to fully customize the credential configurations: Identity Proofing, Intake, Attestation, Device Issuance, Derived Credentials, and Badge Layout.

Note: the majority of configuration options listed in this document are under the Identity Proofing, Attestation, and the Device Issuance tabs.

image-20260521-191346.png

top navigation

image-20260521-191354.png

select and configure policy

image-20260521-191643.png

Credential Policy Configuration Screen

Configuration Settings

Navigate to Admin > Credential Types > Configure Policy >

1

Subscriber Agreement: The Microsoft RTF document listing the subscriber agreement text. This document will be downloaded the workstation clients.

Note: this can also be uploaded or pasted within the web tool.

Go to Policy > Attestation tab

image-20260522-150029.png

2

CMS Card Policy: The CMS card policy this credential type maps to.

Go to Policy > Device Issuance tab

3

CMS Server Key: The DNS Name of the CMS Server.

Go to Policy > Device Issuance tab

4

ID Verification Attestation Text: This is the text the operator will agree to when they are credentialing a user.

Example: When the ID Verification Attestation Text is set in the IDMS, the text will appear for the operator to read and agree to.

Note: this can be uploaded or pasted within the web tool.

Go to Policy > Attestation tab

5

Require Subscriber Agreement: This specifies whether the cardholder (not operator) will perform a digital signature after their credential has been issued.

Go to Policy > Attestation tab

6

Require Operator Digital Signature: This specifies whether the operator will perform a digital signature during the credential issuance process.

Go to Policy > Attestation tab

7

Require operator verify documents during Issuance: This specifies whether the operator will verify documents during the issuance of a credential.

Go to Policy > Attestation tab

8

Credential Type Enforcement Rules:

The IDMS can be configured to query additional user information to ensure an applicant qualifies for a credential.

For example, if an organization has a rule that the applicant must be the “ACCOUNTING” department, the IDMS can query the LDAP Attribute ‘department’ to verify the value is set to “ACCOUNTING” before the credentialing process can continue.

Go to Policy > Identity Proofing tab > 3rd Party Credential Enrollment section

In this example, IDMS will retrieve the value DEPARTMENT LDAP attribute for the user and will then verify it equals the value "ACCOUNTING".

  • If the value does equal "ACCOUNTING", the credentialing process will move forward.

  • If it does not equal the word "ACCOUNTING", the credentialing process will not move forward.

9

Credential Printing Rules:

The following configurations determine whether the credential should be physically printed.

  • Print Credential: To have the credential printed, select YES. If the credential should not be printed, select NO.

  • Print Layout Definition: This is the print layout filename that provides the physical layout of the printed card.

  • Perform Inline Encoding During Print: If the credential is to be encoded during the print process. *Note: This requires the HID Card Encoding Module attachment.

Go to Policy > Identity Proofing tab > Badge Printing section

image-20260522-150617.png

10

Name Change Rules:

To allow the operator to perform a name change, select YES. To prevent the operator from performing a name change, select NO.

Go to Policy > Identity Proofing tab

Completing Updates:

Once the information has been entered and verified, press Save Changes.

You will be prompted to Confirm to apply the changes.

The operat

or will be notified that the credential policy has been updated.

image-20260521-184736.png

Additional Advanced Configuration Capabilities

The following are additional capabilities that can be configured for a given policy.

Item

Procedure

Example

1

Data Validation Rules

The data validation rules specify the criteria an applicant must meet in ordered to quality for the credential type. The rule syntax is: Data attribute condition Data value separated by the “|” character.

In the example, the applicant's givenname must include the text "lra". If the text "lra" is not located in the givenname, the applicant will not be able to qualify for the policy.

2

Credential Policy In-Use Status: This defines whether the credential will be enabled or disabled.

Go to Policy > Credential Policy Configuration

image-20260522-153209.png

3

Certificate Authorities for derived credentials: When issuing derived credentials, determines which certificate authority will be used to generate the certificate for the derived credential.

Go to Policy > Derived Credentials

image-20260522-151906.png

4

3rd Party Credential Enrollment: These security options enable a 3rd party credential holder to authenticate to the system. The configurations are below:

  • Permit Use of Existing Credential for Enrollment: Permits the IDMS to authenticate a 3rd party credential.

  • Credentialing Linking Value: The common value that links the credential and the directory together. This enables the IDMS to look up the identity in an authoritative system to analyze the identity.

  • External Credential Issuing Certificate: The certificate authority that must have issued the 3rd party credential in order for the credential to be verified.

Go to Policy > Identity Proofing tab > 3rd Party Credential Enrollment section

Tip: Setting the External Credential Issuing Certificate: This configuration requires that there be a space after the comma. The configuration also requires no space between the equal sign.

5

Background Investigation Service: The configurations enable a 3rd party background investigation service to enroll and verify the user's identity.

  • Perform Background Investigation Service: Yes, specifies that the applicant will be queued for a background investigation.

  • Background Investigation System: Specifies the service that will perform the background investigation.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.