Low-voltage path · Division 9: Access installation and integration · Lesson 168

Testing granted, denied and expired credentials

Testing granted, denied and expired credentials

What you should be able to do

Test three controlled credential cases on an isolated trainer and explain why each result occurred. Separate credential recognition, authorization, validity, output behavior and physical entry.

Training boundary

Use instructor-approved test identities and credentials with no production door or release circuit connected. Never borrow a real person's badge to improvise a test. Confirm the trainer's configuration and time settings before starting. Keep credential secrets out of the worksheet and screenshots.

Teaching narration

An access decision depends on several conditions. The reader must provide a usable credential to the controller. The credential must have the required validity and the applicable access rules must authorize that opening at that time. Additional configured requirements can affect the decision. Do not interpret every red light or beep as the same failure.

Axis Secure Entry documentation distinguishes credential start/end validity from access rules, which connect cardholders or groups to doors or zones and schedules. It also supports several expiration methods. For this exercise use a fixed, documented expiration instant so the expected condition is clear. Do not substitute first-use or last-use expiry unless the instructor has designed that separate test. [1]

Prepare a small test table with expected results before presenting any card. Confirm each enrolled credential's unique training label, the intended reader and opening, effective permissions, schedule, validity and controller time. Confirm that updates have reached the trainer. Identify and remove unintended test overrides through the authorized configuration process; do not disable required safeguards.

Worked through

A: a known enrolled test credential is current and allowed at the selected opening and time. With all other required conditions met, expect a grant. B: a second known enrolled credential is current but has no applicable permission for this opening. With the other test conditions controlled, expect a denial due to missing authorization. C: a known enrolled credential has passed its fixed expiry. It otherwise has the same required permission and schedule as a valid comparison case. Expect a denial after expiration.

An expired credential is itself a denial case. The title's three categories are teaching cases, not three mutually exclusive event types in every system. The actual event name or reason field depends on the product and integration.

Perform and observe

Present only the intended credential for the current case. Record the test label, opening, timestamp and time zone, expected decision, actual decision and available reason. Observe the trainer's configured output separately. A software grant does not prove a person passed through a door, and a denial does not prove a real door was physically closed or locked.

Axis event documentation distinguishes access-granted and access-denied events and includes several denial categories. Use the actual system's event details rather than inventing a universal "expired" message. A generic denial supports only the limited conclusion that access was denied. Establishing why may require comparing configuration, time and more detailed diagnostics. [2]

Expiry verification

For a stronger expiry test, the instructor can use the same isolated test credential before and after its documented expiry, without changing its door permission or moving the controller clock. Confirm the platform's boundary semantics and test clearly on either side rather than exactly on an ambiguous timestamp. Account for the relevant time zone and propagation state. Keep the trainer disconnected from production outputs throughout the exercise.

Worked through

Test C is labelled "expired" in the worksheet. The event instead says the credential is unknown. The learner proposes marking expiration as passed because access was denied. That is incorrect: an enrollment or identification problem could have caused the denial before expiry was evaluated. Correct the setup, verify recognition through the authorized process, and repeat the controlled expiry test. Retain both the original failure and the retest result.

Troubleshooting discipline

Change one test condition at a time. Check the presented credential, format, reader association, enrollment, time, membership, rule and update status. Do not grant all-day access to every door merely to obtain a green indication. If a supposedly prohibited test grants access, preserve the event and inspect all effective permissions and overrides. The expected result written on paper does not overrule what the system actually did.

Supervised practice

Build the three cases in a mock configuration, with instructor approval. Have a second learner check the expected-result table before running them. Record both a positive test and the two controlled negative tests. Discuss what each result proves and what remains untested, such as mechanical release, egress or network-outage behavior. Afterward, remove or disable temporary test credentials and permissions as directed. Preserve a non-secret test report and document cleanup. Do not leave a test credential in an operating system.

Knowledge check

  1. Is an expired credential normally a denial case?

Answer: Yes, when its validity is enforced under the tested configuration.

  1. Does an unknown-credential denial prove expiry enforcement?

Answer: No.

  1. Why verify time first?

Answer: Validity and schedule decisions depend on the system's time basis.

  1. Does a grant prove physical entry?

Answer: No.

  1. What makes the negative cases useful?

Answer: Controlled conditions and evidence that supports the intended reason.

Sources

[1] Axis Communications, AXIS Camera Station Pro Secure Entry, Add credentials and Add an access rule. https://help.axis.com/en-us/axis-camera-station-secure-entry [2] Axis Communications, VAPIX Event logger service. https://developer.axis.com/vapix/physical-access-control/event-logger-service/

Free study material for low-voltage apprentices. This is a national foundation course: requirements differ by state and by local jurisdiction, and a practice that is common in one place is not a rule everywhere. Nothing here is a licence, a certification, or authority to work unsupervised, and completing it does not count as apprenticeship hours or continuing-education credit. Check the codes adopted where you are working, the licensing authority for that work, and your employer's safety programme. VoltMark is not affiliated with, endorsed by, or sponsored by NFPA, OSHA, NICET, BICSI, FOA, or any state or local licensing authority.