Windows Logon
Windows Logon provides users with the following types of access:
- Access to the operating system with the account password.
- Access to the operating system with the available authentication technologies.
- Access to the remote desktop with the available authentication technologies.
- Access to the operating system with a cached authenticator when there is no connection to Core Server.
Windows Logon supports two-factor authentication, certificates, contactless cards, one-time passwords sent by SMS and email, and others.
In Windows Logon, you can authenticate with the following authenticators:
- Email OTP
- Futronic Provider
- Hardware OTP
- Hardware TOTP
- IronLogic Z2 USB Provider
- MFA Provider
- OMNIKEY Provider
- Passcode
- Secured TOTP
- Smart Card Provider
- SMS OTP
- Software OTP
- Storage SMS OTP
- Telegram Provider (in the mode of sending one-time passwords)
- Windows Password
- the Axidian Key mobile application (in the mode of sending one-time passwords and push notifications with login confirmation)
To keep the data secure when the user is away from the workplace, Windows Logon supports manual and automatic workstation locking — when the authentication device is removed or the screen saver is turned on. Regardless of the locking method, unlocking the workstation always requires the user identity to be confirmed again with an authenticator.
Prerequisites
To use Windows Logon to log in to the system:
- Install and configure the Windows Logon module.
- Register the module license in Management Console.
- Install and configure the authentication providers.
- If required, install a hardware authentication device.
You can log in to the system with an authenticator and manage authenticators only with the permission granted by the system administrator.
Install
- Run the installation file located at
Axidian Access <version number>/Axidian Windows Logon/<version number>. - After the component installation is complete, the system must be restarted. In the installation wizard window, click Yes to restart immediately, or No to do it manually later.
You can deploy Windows Logon on user workstations automatically with Microsoft Group Policy or any other tool that allows you to distribute and install MSI packages on user workstations in bulk (such as Microsoft System Center Configuration Manager).
Configure
You can configure Windows Logon either in Registry Editor or with group policies.
Settings applied with group policies take priority over the settings specified manually in the registry. You can view the group policy settings in the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Axidian-ID\SrvLocator2.
For more information about the module group policies, see the Windows Logon section.
- In registry
- In Group Policy Editor
Open Windows Registry Editor.
Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Axidian-ID\SrvLocator2.Open the properties of the
ServerUrlBasestring parameter.In the Value field, specify the URL of your Core Server in the format
http(s)://full_dns_server_name/am/core.NoteWhen using the HTTPS protocol connection, install a client certificate on each Core Server.
The group policy templates are located in the Axidian Access <version number>\Misc\ADMX Templates folder.
- Add the
AxidianID.ServerUrl.admxpolicy to the device with Windows Logon installed. - Open Group Policy Editor.
- Open Computer Configuration → Administrative Templates → Axidian ID → ClientConnection.
- Enable the Server connection settings policy.
- In the Core Server URL field, specify the address of your Core Server in the format
http(s)://full_dns_server_name/am/core.
Additional features
Additional features of Windows Logon:
- Self-registration and management of authenticators with the management utility.
- Generation of a random password for the user in Active Directory.
- The Axidian Access Paste feature, which allows the password to be substituted automatically in a hidden form when a certain key combination is pressed.
- Concurrent operation of the module with RDP Windows Logon.
- Authentication by Axidian Access when starting an application as an administrator.