> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truu.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Registration Policies

> At the core of the TruU solution is a rich policy engine that determines exactly who has access to what and what the experience is that ensues. Policies can be applied to all Groups, or to specific Groups (either groups from the underlying user directory, or Entitlement Groups defined in TruU).  The policy engine evaluates policy definition based on the first match based on the priority order of the policies.  You can change the evaluation order for policies through drag-and-drop.  Once a policy is created, you can edit the policy (or set the policy to inactive) by clicking on the policy.  This is a step-by-step guide detailing how to Configure Registration Policies on the TruU Admin Console.

**Configuring Registration Policies**

To add a policy, click the **(+)** button at the top of the page

<img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/3169ccc-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=7ff4058aaedc33509f76bd6b69381f8f" alt="" width="1183" height="453" data-path="images/docs/3169ccc-image.png" />

**Mobile Registration Policies**

* **Allow Mobile Registration:**

  * Setting to "True" enables users in the matching group to register a mobile app, with TruU as an authenticating device.  A value of "False" will prevent users from registering

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/8d3385e-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=3af6c185105b8b0086e2862b3fcfc1d9" alt="" width="666" height="756" data-path="images/docs/8d3385e-image.png" />

* **Select Enrollment Workflow:**

  * Enrollment workflows require a self-service component from the registering user, and optionally allow for up to 2 additional identity verification steps (by a manager, and/or an Entitlement Group)

    <img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/5e7596c-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=67c1eaad423208a53970aabf8c93dfe9" alt="" width="666" height="756" data-path="images/docs/5e7596c-image.png" />

* **Use same workflow for Re-enrollment:**

  * By setting this to "False", you can specify a different enrollment workflow for a first time user vs an existing user. For example, you might wish to allow a new hire to enroll with a password on their first day, but then use a passwordless flow for enrollment thereafter

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/a7e9467-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=4a090508adaddea2268f00479c6fce24" alt="" width="666" height="756" data-path="images/docs/a7e9467-image.png" />

* **Allow Public App:**

  * Setting to "True" enables user to register using the TruU mobile app from the public app stores.  A value of "False" will prevent use of the public apps; this should only be selected if deploying TruU by integrating our technology with another app using the TruU SDK, and/or if enabling users for FIDO security keys only

    <img src="https://mintcdn.com/truu-2/rjjBxA7Z_Wk_-34G/images/docs/d83feec-image.png?fit=max&auto=format&n=rjjBxA7Z_Wk_-34G&q=85&s=59c5043aa6b824e5f26fd7bcdd25ae14" alt="" width="666" height="756" data-path="images/docs/d83feec-image.png" />

* **Managed Device Only**:

  * Setting to "True" restricts TruU enrollment to corporate managed mobile devices only

    <img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/b83d41d-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=86a8fc7c0204be8dc51af3cbfb64cbf7" alt="" width="666" height="756" data-path="images/docs/b83d41d-image.png" />

* **Device Biometrics:**

  * Setting to "Enabled" informs the mobile app to have the user enroll their device using the device biometrics. Setting to "Disabled" informs the mobile app that your organization does not wish to use biometrics with TruU and will result in enrollment asking the user to create a TruU app PIN only

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/8adca8d-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=9130c146b757d74b0a571e77a0227a92" alt="" width="666" height="756" data-path="images/docs/8adca8d-image.png" />

* **Enrollment Requirements:**

  * Setting to "Allow PIN Only" enables users to register a mobile device that does not have supported biometrics to enroll.  A value of "PIN + Biometrics" will prevent users from enrolling a mobile device if the device does not have supported biometrics

    <img src="https://mintcdn.com/truu-2/ehCBQgFdl_pQd0MN/images/docs/ad17395-image.png?fit=max&auto=format&n=ehCBQgFdl_pQd0MN&q=85&s=dd4bb8916757fd3516bdffc8035657ea" alt="" width="666" height="756" data-path="images/docs/ad17395-image.png" />

* **Select PIN Profile for Mobile Devices:**

  * Choose a PIN Profile to specify the required PIN length and complexity rules for users enrolling mobile devices

    <img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/2f2688f-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=9fe3c643d9e74ab066145e77de69a97f" alt="" width="666" height="756" data-path="images/docs/2f2688f-image.png" />

**Desktop Registration Policies**

* **Allow Desktop Registration:**

  * Setting to "True" enables users in the matching group to register a computer, with TruU as an authenticating device.  A value of "False" will prevent users from registering

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/a21ab9f-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=98463ba7408e3bb7952f74ababa5c5c6" alt="" width="665" height="755" data-path="images/docs/a21ab9f-image.png" />

* **Select Enrollment Workflow:**

  * Here you can define how your users will enroll with TruU.  Enrollment workflows require a self-service component from the registering user, and optionally allow for up to 2 additional identity verification steps (by a manager, and/or an Entitlement Group)

    <img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/cbc5268-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=f2a46f34b84664d6e8425cabdf69bd11" alt="" width="665" height="755" data-path="images/docs/cbc5268-image.png" />

* **Use same workflow for Re-enrollment:**

  * By setting this to "False" you can specify a different enrollment workflow for a first time user vs an existing user. For example, you might wish to allow a new hire to enroll with a password on their first day, but then use a passwordless flow for enrollment thereafter

    <img src="https://mintcdn.com/truu-2/E6hYbyLPrBHWbQ3m/images/docs/ba5a246-image.png?fit=max&auto=format&n=E6hYbyLPrBHWbQ3m&q=85&s=9e75c644491253b3d2617864969a74c0" alt="" width="665" height="755" data-path="images/docs/ba5a246-image.png" />

* **Managed Device Only (MacOS):**

  * Setting to "True" restricts TruU enrollment to corporate managed Mac computers only

    <img src="https://mintcdn.com/truu-2/L38yxuvvUa8uAW5I/images/docs/0f39217-image.png?fit=max&auto=format&n=L38yxuvvUa8uAW5I&q=85&s=b108525de2880c5f375f8777cf26455d" alt="" width="665" height="755" data-path="images/docs/0f39217-image.png" />

* **Managed Device Only (Windows):**

  * Setting to "True" restricts TruU enrollment to corporate managed Windows computers only

    <img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/50fb5c2-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=fd84755465cf8f4150de8ddb00cfc334" alt="" width="665" height="755" data-path="images/docs/50fb5c2-image.png" />

* **Device Biometrics:**

  * Setting to "Enabled’ informs the desktop authenticator to have the user enroll their device using the device biometrics. Setting to "Disabled" informs the desktop authenticator that your organization does not wish to use biometrics with TruU and will result in enrollment asking the user to create a TruU app PIN only

    <img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/447f955-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=e57dda9644a749c01207b8ace1a38e00" alt="" width="665" height="755" data-path="images/docs/447f955-image.png" />

* **Enrollment Requirements:**

  * Setting to "Allow PIN Only" enables users to register a desktop authenticator that does not have supported biometrics to enroll.  A value of "PIN + Biometrics" will prevent users from enrolling a desktop authenticator if the device does not have supported biometrics

    <img src="https://mintcdn.com/truu-2/YlfY4z_3_-uDkBaP/images/docs/63b8f0f-image.png?fit=max&auto=format&n=YlfY4z_3_-uDkBaP&q=85&s=747b61764576b50ecf4d5e6aa42b467f" alt="" width="665" height="755" data-path="images/docs/63b8f0f-image.png" />

* **Select PIN Profile for macOS:**

  * Choose a PIN Profile to specify the required PIN length and complexity rules for users enrolling Macs (Mac Authenticator is currently available for Early Access customers only)

    <img src="https://mintcdn.com/truu-2/jMF4bYA9yOA_2TKv/images/docs/308d6d9-image.png?fit=max&auto=format&n=jMF4bYA9yOA_2TKv&q=85&s=3e8683d2db63820a9169db6e07ac58ec" alt="" width="665" height="755" data-path="images/docs/308d6d9-image.png" />

* **Select PIN Profile for Windows:**

  * Choose a PIN Profile to specify the required PIN length and complexity rules for users enrolling Windows

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/a6343cf-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=82eaf8c552cd9195b76745fc49084d33" alt="" width="665" height="755" data-path="images/docs/a6343cf-image.png" />

**Agentless Registration Policies**

* **Allow Security Keys:**
  * Setting to "True" enables users to register a FIDO security key to use as an authenticating device for TruU. A value of "False" prevents the registration of FIDO security keys
* **Allowed Verification Types:**
  * Setting to "Passcodes or Biometrics" allows users to enroll any device. Setting to "Passcodes" limits device enrollment to non-biometric hardware keys; whereas "Biometrics" limits enrollment to biometric hardware keys only Note: (1) This feature requires the 24.150 (or higher) Identity Servers. (2) If an allowed list has been created, this policy will be ignored, and the allowed list will be honored
* **Allow Passkeys:**
  * Setting to "True" enables users to register a FIDO passkey to use as an authenticating device for TruU. A value of "False" prevents the registration of passkeys Note: while security keys and passkeys use the same FIDO standard, we differentiate between the two so that you can choose if you want to require a device bound security key or wish to allow a passkey which can be shared across devices (e.g. through iCloud)

**General Registration Policies**

* **Limit Device Enrollment:**

  * Setting to "True" allows you to specify how many devices a user can enroll for authentication.  When set to "True", you must specify how many devices can be enrolled.  If you allow multiple device types to be enrolled by a user (e.g. mobile, computer and 3rd party FIDO devices), you can optionally set limits for each..  A value of "False" enables users to enroll as many devices as they’d like

    <img src="https://mintcdn.com/truu-2/qCK1oWL4jNpZKJ8A/images/docs/93e7aa8-image.png?fit=max&auto=format&n=qCK1oWL4jNpZKJ8A&q=85&s=7b42f0b13d7536c682c228577312fef9" alt="" width="661" height="594" data-path="images/docs/93e7aa8-image.png" />

***

[Configuring Policies](/docs/configuring-policies)

[Configuring Application Policies](/docs/configuring-application-policies)
