If the email addresses to which you want to deliver one-time passwords are in an external domain (such as SMS addresses or external web mail addresses), you must configure your SMTP server to allow passwords to be sent from the appliance to the external domain, as described in Configuring SMTP to Deliver One-Time Passwords.
For each authentication server, you must also specify the directory attribute that stores the email addresses to which OTPs are sent. You must specify a primary attribute; alternatively, you can specify a secondary attribute that is queried when the first one cannot be found.
To configure an authentication server to support one-time passwords
In the AMC, navigate to System Configuration > Authentication Servers.
Click Edit next to the AD (Microsoft Active Directory Basic or Microsoft Active Directory Advanced), LDAP, or local authentication server you want to reconfigure.
Select a Credential type, if applicable.
Click Continue.
Expand the Advanced area,
Scroll down to the One-Time Passwords section and select Use one-time passwords with this authentication server.
Enter the directory attribute for the email address to which one-time passwords will be sent. If the primary attribute exists on the authentication server, it is used, otherwise the secondary attribute, if specified, is queried.