Enabling authentication enforcement for legacy file transfer tools
Who is this article for?
Administrators using Automatic File Transfer (AFT), Header Footer Updater (HFU), or Workflow Designer.
Administrator permissions required.
Ideagen Quality Management Core now offers the ability to require authentication on the web service used by three companion desktop tools: Automatic File Transfer, Header Footer Updater, and Workflow Designer.
Understanding the change
Note: This article applies to Ideagen Quality Management Core version 2026.9.0.0 and 2026.3.1.2 (LTS) onwards.
Previously, requests from these tools were not required to present valid credentials. Enabling this closes that gap.
The tool version requirement below is a consequence of that security change, not a separate upgrade project. Older builds of these three tools were not written to Ideagen Quality Management against the web service, so once authentication is enforced, they need to be replaced with versions that support it. If you don't use one of these tools, its version requirement doesn't apply to you.
The setting is off by default, so nothing changes for you automatically — this is something you opt into, on your own timeline, by updating the relevant tools and then asking Ideagen Support to enable it for your tenant.
Preparing for authentication enforcement
To enable authentication enforcement:
- Decide when you want to close this gap for your tenant (there's no forced deadline, since the setting is off by default).
- Before that date, update whichever of the three tools you use to the minimum version listed below — this is required for enforcement to work correctly.
- Contact Ideagen Support to have authentication enforcement enabled for your tenant. This is the actual security change taking effect.
- After it's enabled, users of the updated tools will be prompted to sign in the first time they use each tool (or after signing out), the same as signing in anywhere else in Ideagen Quality Management Core.
Checking minimum required tool versions
| Tool | Minimum version once enforcement is enabled |
|---|---|
| Automatic File Transfer (AFT) | 4.7.7 |
| Header Footer Updater (HFU) | 4.7.8 |
| Workflow Designer | 4.7.9 |
Important: Do not ask Support to enable enforcement until every tool listed above is updated. Enabling it while an outdated tool is still in use does not just show an error in every case — for Automatic File Transfer specifically, the tool can appear to complete a check-in successfully while the document is not actually checked in. See Understanding tool behaviour after enforcement below.
You can check your installed version from your machine's Installed apps list. Updated installers are available from your usual Ideagen Quality Management Core download page.
Understanding tool behaviour after enforcement
The table below shows the behaviour of each tool if updated to the minimum version or not once enforcement is enabled:
| Tool | If updated to the minimum version | If not updated, once enforcement is enabled |
|---|---|---|
| Automatic File Transfer (AFT) | Prompts for sign-in on first use (or after sign-out); stays signed in if "Remember me" is selected. |
This is the tool to watch most closely — it can fail in two different ways once enforcement is on:
|
| Header Footer Updater (HFU) |
Applies headers/footers as before, after signing in once. |
The tool shows a visible error and does not apply the header/footer. No silent failure. |
| Workflow Designer |
Prompts for sign-in before attaching a diagram to a workflow. |
The tool does not attach the diagram; no credential prompt appears. |
Frequently asked questions
Why is Ideagen making this change?
To close a gap where these three companion tools could reach Ideagen Quality Management Core's file transfer web service without authenticating. This brings them in line with the rest of Ideagen Quality Management Core, where signing in is already required.
Do I have to enable this setting right away?
No — it's off by default and stays off until you ask Support to enable it. We recommend doing so as soon as your tools are updated, but the timing is yours to decide.
Will this affect normal document check-in/check-out in IQM Core?
No. This change is specific to the three companion desktop tools listed above. Standard check-in/check-out through the Ideagen Quality Management Core web interface is unaffected.
What if I'm running an older version of one of these tools and don't update it?
For Header Footer Updater and Workflow Designer, the tool will visibly fail — you'll see an error and know to update. For Automatic File Transfer, the risk is higher: a check-in can appear to succeed while the document is not actually saved. We recommend confirming AFT is updated everywhere it's used, before enabling enforcement, rather than relying on users to notice a failure.
Who do I contact with questions?
Please raise a request with Ideagen Support, referencing this article.