Passtoken options for ESF Manager are currently set by editing the text in the Configuration Information area on the "Security" tab in the region configuration in MFDS (or the "Default ES Security" or "MF Directory Server" tabs in the security options in MFDS).
You can restrict the use of passtokens in any Enterprise Server component that uses a particular Security Manager configuration by setting the following in that area:
[Passtoken] allow=option
where option is one of none (disable passtokens), generate (allow passtoken generation but not use), signon (allow passtoken use for signon but not generation), both (allow both generation and signon), or yes (synonym for both).
Allowing only generation may be useful for a region that makes ISC requests to another region but does not receive them, and conversely allowing only signon may be useful for a region that receives remote requests but never makes them.