Face Recognition as an Authentication Method

Applies to iOS and Android devices.

Imprivata Mobile Access Management supports face recognition as an authentication method for device check out, using the integration with Imprivata Enterprise Access Management as the identity provider.

Face Recognition Authentication Methods for Device Check Out

NOTE:

Some combinations of authentication factors available in Imprivata Enterprise Access Management are not supported by Mobile Access Management for device Check Out.

The following table illustrates the EAM primary and secondary authentication method selections and the resulting Check Out behaviors in MAM when used with face recognition.

Primary Secondary Device Check Out Behavior
Check Out is initiated by the user tapping their proximity card on a Launchpad
Proximity Card Face recognition
  • User taps their proximity card on the Launchpad's proximity card reader.

  • The device is selected.

  • Imprivata Locker lights up the device's display screen.

  • Imprivata Locker app prompts for face authentication.

    • If the user's face is already enrolled, the user's facial biometric is successfully captured and the device unlocks.

    • If the user's face is not enrolled, Imprivata Locker prompts the user to enroll their face and to consent to the biometric capture. The user's facial biometric is successfully captured and the device unlocks.

Enabling Face recognition authentication requires that you:

  • Configure a connection to the Imprivata Cloud Platform.

  • Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management portal.

  • Configure Entra ID and sync your users with the Imprivata Cloud Platform.

    After configuring Entra ID and syncing users with the Imprivata Cloud Platform, verify that the users exist in the Imprivata Access Management portal (access.imprivata.com).

  • Configure a user policy to enable Face recognition.

Prerequisites

Take note of the following prerequisites:

Requirements

  • Users in a policy enabled for face recognition must be synced from Active Directory (AD) to Entra ID.

  • The cloud must be synced from AD to Entra ID with Entra Connect.

  • Each user in scope for the facial recognition workflow must exist within Entra ID and each user must also be allocated a P1 or higher Microsoft license.

  • Internet access is required for facial biometric authentication.

    If the device cannot connect with your Imprivata Cloud Platform, an error message will appear during authentication. In this scenario, the user can select another authentication method (password / Imprivata PIN, etc) to complete the authentication.

  • Imprivata Licensing: Face recognition authentication requires an Authentication Management license and a Remote Access license.

  • Imprivata Locker app requirements:

    • iOSImprivata Locker for iOS 4.0 or later.

    • AndroidImprivata Locker for Android 2.0 or later.

    • The user must grant access to the device's camera to use face recognition.

      BEST PRACTICE:

      To ensure the highest quality possible, the initial enrollment of a user's face should be done without a mask.

      Subsequent authentications can be done with a mask.

Additional Resources

For more information, see the Imprivata Enterprise Access Management online help.

Configure the Connection to the Imprivata Cloud Platform

Enabling Face recognition requires a connection to the Imprivata Cloud Platform. You need the following to complete the configuration:

  • Access to the Imprivata Appliance Console.

  • Access to the Imprivata Admin Console.

  • Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).

NOTE:

If you have already configured a connection to the Imprivata Cloud Platform, you can skip this step.

You can use either of the following methods to configure the connection.

Configure Entra ID as the Identity Provider

Configure Any Other Third-Party IdP

The following are generic steps to configure any external third-party IdP to authenticate users to the Imprivata Access Management portal. For example, these steps apply to Ping Identity and Okta.

To configure your IdP:

  1. Open the Imprivata Cloud Tenant Setup wizard.

  2. If you have not already, agree to the Cloud Features Agreement and enter information about your organization.

  3. Go to the Identity Provider Connect screen.

  4. Copy the Imprivata SP metadata URL and provide it to your IdP. When configuring the IdP's application:

    • Specify https://access.imprivata.com for the single sign-on URL.

    • Recommended: configure email address as the NameID format for user identity.

    • Recommended: configure Group ID (rather than group name) as the source attribute for group claims.

  5. Enter the SAML IdP metadata URL, and click Continue.

  6. Enter the SAML name/value pair that identifies users with administrative access, and click Continue.

  7. Click Go to Access URL: access.imprivata.com to test the authentication workflow to access Imprivata Access Management.

Configure Microsoft Entra ID for EAM

Configure additional items in Microsoft Entra ID for Imprivata Enterprise Access Management face recognition.

After configuring Entra ID and syncing users with the Imprivata Cloud Platform, verify that the users exist in the Imprivata Access Management portal (access.imprivata.com).

Configure Enterprise Access Management

In Enterprise Access Management, configure the user policy authentication methods and grace periods for MAM.