
RSA SecurID Software Token 4.1 Administrator’s Guide
A: Customizing the Application 89
ValidDevices
The SecurID desktop application supports storing tokens in the RSA token database
on the local hard drive or on a supported TPM, biometric device, or another supported
device plug-in.
To control which devices users can access, you can create a device whitelist (a list of
supported devices). Using a whitelist ensures that users can import, view, change the
name of, and delete only those tokens that are stored in the devices specified in the
whitelist. If a user connects a device that is not in the whitelist, the device is not
displayed in the Token Storage Devices screen.
If you do not use a device whitelist, the user can import tokens to any device that is
recognized by the system and allowed by the token’s device binding settings.
Create a Device Whitelist
Use the ValidDevices policy to create a device whitelist. The values must be
comma-separated Globally Unique Identifiers (GUIDs), as shown in the following
example. Angle brackets are not required.
8f94b026-d362-4554-ac52-3b01fa33b6f,7484g337...
Obtain the device GUIDs from the application.
To obtain device GUIDs:
1. Click Options > Token Storage Devices.
2. In the left pane, click the device icon for the first device that you want to include
in the whitelist.
For example, the following figure shows two installed devices. The Local Hard
Drive (RSA) device is selected, and the associated GUID is displayed in the
Device Type field.
Comentarios a estos manuales