Signing in to Nova
This page describes signing in to Nova itself. How Nova manages accounts and passwords in target systems is described under Accounts and passwords.
Who can sign in
Only active identities with an active Nova account – that is, an active account on the “Nova IAM” system – can sign in. The statuses an identity can have are described under Identities and their status.
Nova ends running sessions immediately when
- the identity's status changes to Suspended or Terminated,
- its Nova account is locked, or
- its password is changed.
In addition, every session has a maximum lifetime, after which a new sign-in is required.
Sign-in methods
| Method | Note |
|---|---|
| Password | Nova stores only a salted hash of the password. |
| One-time code by email | “Email code” tab on the sign-in page |
| Single sign-on with Microsoft Entra ID | “Login with Microsoft Entra”, if set up |
| Second factor (TOTP) | with the “Native MFA (TOTP)” add-on |
Every method passes the same checks – including the second factor where it is required. Administrators decide whether the second factor is mandatory for administrators or for all identities.
The “Native MFA (TOTP)” add-on is switched off by default; administrators enable it under “Administration” → “Plugins”.
Password rules
Passwords that identities use to sign in to Nova are subject to three kinds of rules:
- Minimum length and composition – set under “Administration” → “Provisioning” → “Password Rules”,
- Password history – recently used passwords cannot be set again,
- Maximum age – once it is exceeded, the identity must choose a new password when signing in.
Administrators set the history and the maximum age in the “Nova Login Policy” under “Administration” → “Identity Management” → “Authentication”.
Failed attempts
After repeated failed attempts, Nova locks the Nova account. Administrators set the threshold, the counting window and the duration of the lock in the “Nova Login Policy” as well. Wrong one-time codes and wrong second-factor codes count like wrong passwords.
Self-registration
Self-registration, where a person creates an identity for themselves when signing in, is switched off by default.
Nova as a sign-in service for other applications
With the “OIDC Identity Provider” add-on, Nova also signs identities in to other applications, acting as an OpenID Connect provider. The same rules apply as for signing in to Nova. The add-on is switched off by default.
Nova records sign-ins and failed attempts in the “Audit Log” – see Logs.