Updated Date: 07/07/2026
Creating an Ephemeral Authentication Configuration
Before you set up ephemeral authentication, make sure that basic system configuration is complete including configuring network interfaces, routes, VLANs, self IPs, DNS, and NTP.
You create an Ephemeral Authentication Configuration to specify the authentication method and ephemeral password usage for privileged user access.
-
On the Main tab, click Access > Ephemeral Authentication > Authentication Configuration.
-
Click Create.
-
For Name, type a name for the Ephemeral Authentication Configuration.
-
From the Authentication Method list, select the authentication method or methods (LDAP, RADIUS, or both) to use for ephemeral authentication.
Note: Enable only one authentication type (LDAP or RADIUS) if associating this Authentication Configuration with an SSO configuration (HTTP Basic or Form Based supported).
-
Select One Time Only to enable one-time authentication using the ephemeral password.
If not selected, the ephemeral password can be used multiple times until it expires.
-
For Expiration in Minutes, type the number of minutes after which the ephemeral password expires.
Note: This value applies only when One Time Only is not selected.
-
Click Save.
Access Policy Manager creates an Authentication Configuration and adds it to the list. You can use this in one or more Access Configurations or in an SSO configuration (HTTP Basic or Form Based are supported).