Skip to main content

IronLogic Z2USB

Smart card removal behavior​

IronLogic Z-2 USB Provider supports the Microsoft security policy Interactive logon: Smart card removal behavior.

With this policy, you can define the action performed when a smart card is removed from the user workstation.

Timeout of the action performed on smart card removal​

Note

Configuring the policies is required to increase the security level; however, IronLogic Z-2 USB Provider works properly with the default policy values as well.

The policy of the Windows Logon section defines the duration of the standard and the service timeout after the authentication device is removed.

The policy sets the time interval in seconds between the smart card removal and the action performed according to the Windows Interactive logon: Smart card enhanced removal behavior policy.

The standard timeout prevents the computer from being locked automatically if the authentication device is removed accidentally.

The service timeout prevents the computer from being locked automatically in cases when removing the authentication device in use is necessary (registering an additional authenticator, accessing the system on behalf of another account with another authenticator, and so on). To activate the service timeout, press and hold the [Ctrl]+[L] key combination before removing the device.

If the policy is not set or is disabled, no timeout is provided before the workstation is locked automatically.

Use the contactless card identifier in the ACS format​

The policy defines the storage format of card identifiers in the Axidian Access database. This makes it possible to ensure compatibility with the identifier storage format of access control systems (ACS).

By default, the full card information is stored:

  • Type
  • Manufacturer
  • Batch number and card identifier