Optional settings
With Windows Logon, you can:
Enable random password generation
When using the Windows Logon module, you can set up random password generation for the user in Active Directory. For this setting to work, disable the User cannot change password and Password never expires options in the user properties in Active Directory.
A random password for the account is generated when the current password expires. If a random password was generated for the account, the next login to the system is possible only with an authenticator.
To enable random password generation:
- In the Management Console sidebar, go to the Policies section.
- Open the required policy.
- On the Applications tab, click Windows Logon.
- For the Active Directory account password setting, select Generate random.
- Click Save.
The passwords for all users in this policy are changed unless this contradicts their properties in Active Directory.
The Management Console event log displays event 1091 The user password has been successfully changed automatically. Users can log in to the system only with the added authenticators, without using the domain password.
If the user has no registered authenticators, at the first login to the system, after entering the domain password, the authenticator management utility opens and prompts to register the first authenticator.
After the authenticator is registered, the user password is generated and changed.
If the domain password was changed by the administrator, a message about password desynchronization appears at the login to the system. Click OK and enter the password set by the administrator. After that, the password is changed automatically.
If authenticator caching is allowed for the account, the data is saved to the local computer memory at the subsequent login with an authenticator. Then, when there is no connection to Core Server, you can log in to the system with the cached authenticator data.
If the password change requirement is enabled for the user
If the domain password change requirement is enabled in the user properties in Active Directory and random password generation is allowed, a random password is generated at the next authentication with Axidian Access technology. A message about the successful automatic password change is displayed.
Configure automatic substitution of the hidden password with Axidian Access Paste
When a password must be entered to log in to an application, you can do it securely with the Axidian Access Paste feature. It allows the hidden password to be substituted automatically into the input field with a certain key combination. By default, this is [CTRL] + [ALT] + [V].
You can enable and disable the Axidian Access Paste feature in the Paste Tool application. To do this:
Right-click the Paste Tool icon in the Windows notification area.
Select the required item of the context menu:
- Enable Paste to enable or disable the feature. The feature is enabled by default.
- Run at startup so that Paste Tool starts when Windows boots. This setting is enabled by default.
- Exit.
To substitute the password in a hidden form:
- In the application window, place the cursor in the password input field.
- Press the key combination for password substitution.
- The Authentication window opens. Confirm your identity in any available way.
After successful authentication, the hidden password is displayed in the input field.
Configure concurrent operation with RDP Windows Logon
If the Windows Logon and RDP Windows Logon modules are installed on the same device, configure the policy for Windows Logon.
- In registry
- In Group Policy Editor
- Go to the device with the RDP Windows Logon and Windows Logon modules installed.
- Open Registry Editor.
- Open Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Axidian-ID\Logon for Windows.
- Create a parameter of the DWORD type named
CredProvFilterand set it to the value 2.
- Go to the device with the RDP Windows Logon and Windows Logon modules installed.
- Open Group Policy Editor.
- Open Computer Configuration → Administrative Templates → Axidian ID → Windows Logon.
- Enable the Credential Provider settings policy.
- For the Display of login methods parameter, select the All except the password value.
Use authentication when running as an administrator
On devices running Windows 7, the Windows Logon module sends an authentication request when the Run as administrator command is used. After this command is run, the account selection dialog is displayed, then the Axidian Access Authentication window. Depending on the operating system version, the account selection window may look different.