Skip to main content

Omnikey

Smart card removal behavior​

OMNIKEY Provider supports the Windows security policy Interactive logon: Smart card removal behavior.

With this policy, you can define the action performed when a smart card is removed from the user workstation.

Timeout of the action performed on smart card removal​

The policy of the Windows Logon section defines the duration of the standard and the service timeout after the authentication device is removed.

The policy sets the time interval in seconds between the smart card removal and the action performed according to the Windows Interactive logon: Smart card enhanced removal behavior policy.

The standard timeout prevents the computer from being locked automatically if the authentication device is removed accidentally.

The service timeout prevents the computer from being locked automatically in cases when removing the authentication device in use is necessary (registering an additional authenticator, accessing the system on behalf of another account with another authenticator, and so on). To activate the service timeout, press and hold the [Ctrl]+[L] key combination before removing the device.

If the policy is not set or is disabled, no timeout is provided before the workstation is locked automatically.

Use PACS data​

Information

The policy is applied to user workstations.

When enabled, this policy allows using PACS data instead of the card identifier.

It requires no configuration.