Face Recognition as an Authentication Method

Imprivata MDA supports face recognition as an authentication method.

Assumptions

The configuration tasks in this topic assume that:

Requirements

  • The Imprivata Cloud Connect service to your tenant on the Imprivata Cloud Platform must be up and running.

  • For Entra ID:

    • Users in a policy enabled for face recognition must be synced from Active Directory (AD) to Entra ID.

    • The cloud must be synced from AD to Entra ID with Entra Connect.

    • Each user in scope for the facial recognition workflow must exist within Entra ID and each user must also be allocated a P1 or higher Microsoft license.

  • Internet access is required for facial biometric authentication.

    If the device cannot connect with your Imprivata Cloud Platform, an error message will appear during authentication. In this scenario, the user can select another authentication method (password / Imprivata PIN, etc) to complete the authentication.

  • Imprivata MDA 8.0 or later on the devices.

  • Imprivata Licensing: Face recognition authentication requires an Authentication Management license and a Confirm ID for Remote Access license, in addition to your Imprivata MDA licenses. For more information, see Imprivata Licensed Features.

  • Face recognition requires camera permission to be granted on the device.

    If you add the AppConfig flag requireCameraPermission, the camera permission is handled along with other permissions upon Imprivata MDA's first run.

    Imprivata MDA also checks whether the permission is granted before starting the camera for face recognition. If the permission is not granted, Imprivata MDA prompts the user to grant it.

Considerations

Consider the following information for face recognition:

  • Face recognition is not supported with offline mode.

  • Biometric data is not stored on the device.

  • Supports face masks.

    BEST PRACTICE:

    To ensure the highest quality possible, the initial enrollment of a user's face should be done without a mask.

    Subsequent authentications can be done with a mask.

  • Imprivata MDA face recognition is not supported for the Epic Rover witness authentication workflow in this release.

Configure an IdP to Authenticate Users to the Imprivata Access Management Console

Configuring an IdP is required to authenticate administrators to the Imprivata Access Management console. You need access to the Imprivata Access Management console to synchronize your users with the Imprivata Cloud Platform.

Configure the Connection to Imprivata Cloud Platform

Enabling Face recognition requires a connection to the Imprivata Cloud Platform. You need the following to complete the configuration:

  • Access to the Imprivata Appliance Console.

  • Access to the Imprivata Admin Console.

  • Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).

IMPORTANT:

Imprivata Access Management Setup supports several Imprivata products on the Imprivata Cloud Platform.

Some steps may require information from the Imprivata Admin Console or your identity provider (IdP) console.

Some steps may not be required for configuring Imprivata MDA.

Configure Entra ID and Sync Your Users with the Imprivata Cloud Platform

Configure the Enterprise Access Management User Policy

  1. In the Imprivata Admin Console, go to the User policies page > Authentication tab > Desktop Access authentication section.

  2. Select Face recognition as a primary factor.

  3. Select a second factor for Face recognition:

    • No second (not recommended)

      • In EAM 25.4 and later, the no second factor option has been removed.

      • In EAM 25.3 and earlier, the Imprivata Admin Console still displays the option for no second factor. It is not a recommended configuration.

    • Imprivata PIN

    • Password

    • Proximity Card

    • Security Key

      BEST PRACTICE:

      For enhanced protection against sophisticated attacks, pair Face authentication with a strong second factor like proximity card or security key.

  4. Select another primary factor.

    For example, if users in this policy must use a different authentication method when Face recognition authentication is not available.

  5. Specify the grace period for authentication:

    • In EAM 25.3 and later, in the Authentication method options section > Face recognition, specify the grace period in the Grace period for second factor after face recognition boxes, up to 24 hours 59 minutes.

  6. Click Save.