The first login to the system
If the user has no registered authenticators, the domain password must be used for the first login to the system.
If the user is allowed to register authenticators, the First login wizard starts at the login to the system and prompts to register the first authenticator.
You can register the authenticator immediately or later at any convenient time.
- To register an authenticator, in the Authenticator management window, select one of the available authentication methods.
- To log in to the system without registering an authenticator, click Finish. In this case, the First login wizard is displayed at each subsequent login to the system until the first authenticator is registered.
If no authentication providers are detected on the workstation, registering authenticators is not possible. The following error appears: No authentication provider was found in the system. You must install a provider and configure the secure login to the system again.
If the user has SMS OTP or Email OTP authentication configured, the login to the system is performed with the configured authenticator, after which a message about password desynchronization appears.
Register the first authenticator
To register the first authenticator:
In the wizard window, select the authentication method. The wizard window displays the installed authenticators that are enabled in the Windows Logon properties in the policy card.
Perform the required actions following the prompts in the Authenticator management window. The window appearance and the actions depend on the selected authentication method.
If you want to return to the previous page and change the settings or select another login method, click Back.
After the authenticator is registered, the Authenticator management window displays the message The new authenticator has been successfully registered. You can add an arbitrary text comment to the registered authenticator if this action is allowed by the system administrator.
To complete the authenticator registration, click Save.
The type of the registered authenticator and the comment to it are displayed in the Authenticator management window.
If the user is allowed to add several authenticators, you can proceed to register them by clicking Add a login method. Depending on the granted permissions, you can also modify, verify, or delete a registered authenticator.
At the next login to the system, the login method with the registered authenticator is available.