Passwordless Authentication with Device-Bound Passkey

Imprivata Enterprise Access Management supports passwordless authentication for Desktop Authentication with a device-bound passkey.

BEST PRACTICE:

Only enable device-bound passkey at single user computers (Type 1) .

Enable in User Policy

  1. In the Imprivata Admin Console, go to UsersUser policies.

  2. Go to AuthenticationDesktop Access authentication.

  3. Select Device-bound passkey as a second factor for one or more primary factors.

    BEST PRACTICE:

    To make the enrollment 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway:

    • Imprivata ID or device-bound passkey

    • Imprivata PIN or device-bound passkey

    • Security Key or Imprivata PIN or Proximity Card or Device-bound passkey

  4. Click Save.

Enable in Computer Policy

  1. In the Imprivata Admin Console, go to ComputersComputer policies.

  2. Select a computer policy to configure.

    BEST PRACTICE:

    Only enable device-bound passkey at single user computers (Type 1) .

  3. Go to GeneralAuthentication and select Enable Device-bound passkey.

  4. Click Save.

Expected Workflow

  1. To enroll the device-bound passkey, the user logs into the desktop or the enrollment utility with two authentication methods.

    The device-bound passkey is now enrolled.

  2. The next time the user logs into the desktop, the user will only need to complete their primary factor of authentication. The device-bound passkey is the second factor and is completed 'silently' for them.

Deleting Enrollment

The device-bound passkey enrollment can be deleted from the user or computer page in the Imprivata Admin Console.

Deleting on the User Page

  1. In the Imprivata Admin Console, go to UsersUsers.

  2. Select the user whose enrollment you want to delete.

  3. Go to Security KeyDevice-bound passkey.

    Enrolled passkeys are listed by hostname and enrollment date and time.

  4. Select the enrollment to delete.

  5. Click Save.

Deleting on the Computer Page

  1. In the Imprivata Admin Console, go to ComputersComputers.

  2. Select the computer where the user enrolled.

  3. Go to Device-bound passkeys.

    Enrolled users are listed by username and enrollment date and time.

  4. Select the enrollment to delete.

  5. Click Save.