Grace Period for Imprivata Authentication

Grace period is an Imprivata setting that lets a user re-authenticate with just a proximity card tap, no PIN or password, for a configurable time after their last multi-factor login. It applies to any Imprivata policy that pairs a proximity card with a PIN or password as the second authentication factor.

  • Initial login — The user taps their card, enters the PIN or password, and the session opens. The grace-period timer starts at that point.
  • Re-authentication within the grace period — Tapping the card alone unlocks the screen or opens a new session, with no PIN or password prompt.
  • Re-authentication after the grace period — Tapping the card prompts for the PIN or password again, the same as the initial login.

No eLux configuration is required beyond enabling Imprivata as the authentication type for the device’s OU — the grace period itself is controlled entirely by the Imprivata server policy below.

Configuration

Configure the grace period on the Imprivata Appliance Console:

  1. Open or create a user policy under User policies.
  2. Under Authentication method options → Proximity card, set the policy to Proximity Card + PIN or Proximity Card + Password.
  3. Set Grace period for second authentication factor to the desired duration, in the format hours : minutes (0–24 hours, 0–59 minutes).

    Grace period for second authentication factor

  4. Save the policy and assign it to the relevant users, group, or OU.

Good to Know

  • The grace-period timer resets on every successful PIN or password login — it isn’t a fixed once-per-day window.
  • Both the proximity card and the PIN or password modality must already be enrolled for the user before the policy can apply.
  • A duration of 0 disables the grace period, even if the policy itself is enabled.
  • Losing connectivity to the Imprivata agent forces fail-secure behavior — the PIN or password prompt reappears even within the grace period.
Grace Period for Imprivata Authentication