Passwordless Authentication with Device-Bound Passkey
Imprivata Enterprise Access Management supports passwordless authentication for Desktop Authentication with a device-bound passkey.
Only enable device-bound passkey at single user computers (Type 1) .
Enable in User Policy
-
In the Imprivata Admin Console, go to Users > User policies.
-
Go to Authentication > Desktop Access authentication.
-
Select Device-bound passkey as a second factor for one or more primary factors.
BEST PRACTICE:To make the enrollment 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway:
-
Imprivata ID or device-bound passkey
-
Imprivata PIN or device-bound passkey
-
Security Key or Imprivata PIN or Proximity Card or Device-bound passkey
-
-
Click Save.
Enable in Computer Policy
-
In the Imprivata Admin Console, go to Computers > Computer policies.
-
Select a computer policy to configure.
BEST PRACTICE:Only enable device-bound passkey at single user computers (Type 1) .
-
Go to General > Authentication and select Enable Device-bound passkey.
-
Click Save.
Expected Workflow
-
To enroll the device-bound passkey, the user logs into the desktop or the enrollment utility with two authentication methods.
The device-bound passkey is now enrolled.
-
The next time the user logs into the desktop, the user will only need to complete their primary factor of authentication. The device-bound passkey is the second factor and is completed 'silently' for them.
Deleting Enrollment
The device-bound passkey enrollment can be deleted from the user or computer page in the Imprivata Admin Console.
Deleting on the User Page
-
In the Imprivata Admin Console, go to Users > Users.
-
Select the user whose enrollment you want to delete.
-
Go to Security Key > Device-bound passkey.
Enrolled passkeys are listed by hostname and enrollment date and time.
-
Select the enrollment to delete.
-
Click Save.
Deleting on the Computer Page
-
In the Imprivata Admin Console, go to Computers > Computers.
-
Select the computer where the user enrolled.
-
Go to Device-bound passkeys.
Enrolled users are listed by username and enrollment date and time.
-
Select the enrollment to delete.
-
Click Save.