Form authentication upgrade guide
When upgrading from Invicti Enterprise to Invicti Platform, form authentication settings carry over automatically using one of two paths, depending on how the original configuration was set up. This document explains the two upgrade paths, what isn't carried over, and what you need to configure manually after the upgrade.
For a full breakdown of authentication settings that transfer during the upgrade, refer to the IE to Invicti Platform upgrade reference document.
Why this matters
Not all form authentication in Invicti Enterprise carries over to the same feature in Invicti Platform. The upgrade path depends on whether the default authentication script was modified. If the wrong type is assigned after the upgrade, scans may authenticate incorrectly or fail to detect logged-out states. Knowing which path applies lets you verify the result and apply the right post-upgrade steps.
Two upgrade paths
Form authentication carries over based on whether the script was customized in Invicti Enterprise:
| Invicti Enterprise configuration | Carries over to |
|---|---|
| Default script, unchanged | Simple Form Authentication |
| Custom script | Login Sequence Recording |
If the authentication script was left at its default and never modified, the configuration carries over as Simple Form Authentication in Invicti Platform.
If a custom script was used, it carries over as a Login Sequence Recording (LSR). The upgrade carries over the login steps, recorded navigation, form submissions, and credentials.
What isn't carried over
Regardless of which path applies, the following settings aren't transferred:
- Session validation patterns: the scanner can't detect authenticated vs unauthenticated states until you define these.
- Logout restrictions: without configuration, the scanner may trigger logout actions during a scan.
Configure these manually in Invicti Platform after the upgrade.
Post-upgrade configuration
After the upgrade:
- Open the target's authentication settings in Invicti Platform.
- Confirm the authentication type matches what you expect - Simple Form Authentication or Login Sequence Recording.
- Verify that login steps execute successfully.
- Define session validation patterns to confirm the authenticated state.
- Configure logout restrictions to prevent unintended session termination.
- Save and re-test the authentication flow.
For step-by-step guidance, refer to the Simple Form Authentication and Login Sequence Recording documents.
Troubleshooting
The authentication type in Invicti Platform doesn't match what I expected
The upgrade path depends entirely on whether the authentication script was modified in Invicti Enterprise. If the default script was customized at any point, it carries over as a Login Sequence Recording — not Simple Form Authentication. Open the target's authentication settings in Invicti Platform to confirm the type. If it's incorrect, reconfigure it manually using the correct authentication method.
The scanner isn't detecting the authenticated state after the upgrade
Session validation patterns aren't carried over during the upgrade. Without them, the scanner can't distinguish between an authenticated and unauthenticated response. Open the target's authentication settings in Invicti Platform and define session validation patterns. Refer to the Targets authentication documents for step-by-step guidance.
The scanner is triggering logout actions during a scan
Logout restrictions aren't carried over during the upgrade. Without them, the scanner may follow links or submit forms that end the authenticated session. Configure logout restrictions in the target's authentication settings in Invicti Platform to prevent this. Refer to the Targets authentication documents for guidance.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center