Face Recognition as an Authentication Method

Applies to iOS and Android devices.

Imprivata Mobile Access Management supports face recognition as an authentication method for device check out, using the integration with Imprivata Enterprise Access Management as the identity provider.

Face Recognition Authentication Methods for Device Check Out

NOTE:

Some combinations of authentication factors available in Imprivata Enterprise Access Management are not supported by Mobile Access Management for device check out.

The following table illustrates the EAM primary and secondary authentication method selections and the resulting check out behaviors in MAM when used with face recognition.

Primary Secondary Device Check Out Behavior
Check Out is initiated by the user tapping their proximity card on a Launchpad
Proximity Card Face recognition
  • User taps their proximity card on the Launchpad's proximity card reader.

  • The device is selected.

  • Imprivata Locker lights up the device's display screen.

  • Imprivata Locker app prompts for face authentication.

    • If the user's face is already enrolled, the user's facial biometric is successfully captured and the device unlocks.

    • If the user's face is not enrolled, Imprivata Locker prompts the user to enroll their face and to consent to the biometric capture. The user's facial biometric is successfully captured and the device unlocks.

Enabling Face recognition authentication requires that you:

  • Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management console.

  • Configure a connection to the Imprivata Cloud Platform.

  • Configure Entra ID and sync your users with the Imprivata Cloud Platform.

    After configuring Entra ID and syncing users with the Imprivata Cloud Platform, verify that the users exist in the Imprivata Access Management console (access.imprivata.com).

  • Configure a user policy to enable Face recognition.

Prerequisites

Take note of the following prerequisites:

Requirements

  • Users in a policy enabled for face recognition must be synced from Active Directory (AD) to Entra ID or maintained in Entra ID only.

  • The cloud must be synced from AD to Entra ID with Entra Connect.

  • Each user in scope for the facial recognition workflow must exist within Entra ID and each user must also be allocated a P1 or higher Microsoft EntraID license.

  • Imprivata Licensing: Face recognition authentication requires an Authentication Management license and a Remote Access license.

  • Imprivata Locker app requirements:

    • iOSImprivata Locker for iOS 4.0 or later.

    • AndroidImprivata Locker for Android 2.0 or later.

    • Internet access on the device is required for facial biometric authentication.

      If the device cannot connect with your Imprivata Cloud Platform, an error message will appear during authentication. In this scenario, the user can select another authentication method (password / Imprivata PIN, etc) to complete the authentication.

    • The user must grant access to the device's camera to use face recognition.

      BEST PRACTICE:

      To ensure the highest quality possible, the initial enrollment of a user's face should be done without a mask.

      Subsequent authentications can be done with a mask.

Additional Resources

For more information, see the Imprivata Enterprise Access Management online help.

Configure an IdP to Authenticate Users to the Imprivata Access Management Console

Configuring an IdP is required to authenticate administrators to the Imprivata Access Management console. You need access to the Imprivata Access Management console to synchronize your Entra ID users with the Imprivata Cloud Platform.

NOTE:

If you have already configured access to the Imprivata Access Management Console, you can skip this step.

You can configure any third-party IdP. For example, Microsoft Entra ID.

  • Configuring an external IdP lets you use your organization’s existing identity infrastructure to authenticate administrators.

    • Configuring Entra ID as an IdP has the added benefit of letting your non-administrative users enroll their face as an authenticator using My Imprivata Identity from any device.

Configure the Connection to the Imprivata Cloud Platform

Enabling Face recognition requires a connection to the Imprivata Cloud Platform. You need the following to complete the configuration:

  • Access to the Imprivata Appliance Console.

  • Access to the Imprivata Admin Console.

  • Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).

NOTE:

If you have already configured a connection to the Imprivata Cloud Platform, you can skip this step.

You can use either of the following methods to configure the connection.

Configure Microsoft Entra ID and Sync Your Users with the Imprivata Cloud Platform

For Entra ID enterprises, additional Entra ID configuration is required to enable Face recognition.

After configuring Entra ID and syncing users with the Imprivata Cloud Platform, verify that the users exist in the Imprivata Access Management console (access.imprivata.com).

Configure Enterprise Access Management User Policy

In Enterprise Access Management, configure the user policy authentication methods and grace periods for MAM.