Windows Logon
Windows Logon provides the ability to access Windows using strong authentication technologies in the Microsoft Active Directory environment. For this, the Windows Logon agent is installed on user workstations.
The agent installer is implemented as a standard MSI (Microsoft Windows Installer) package. This allows you to install and update the system in bulk quickly, using various tools such as Active Directory group policies, Microsoft System Center Configuration Manager (SCCM), and others.
For integration with the Windows operating system, the standard Credentials Provider mechanism for implementing a custom user authentication interface is used. This technology allows third-party developers to integrate their own authentication technologies with the Windows interface. It makes it possible not only to log in to Windows with Axidian Access technology, but also to authenticate with Axidian Access inside the operating system, for example when accessing domain resources or web applications.
Windows Logon supports all the authentication technologies available in Axidian Access — smart cards, RFID cards, one-time passwords.
Install and configure Windows Logon
Authentication technologies
Windows Logon supports the following authentication technologies:
- the domain password
- TOTP and HOTP one-time passwords
- one-time codes sent by SMS and email
- one-time codes and push notifications in the Axidian Key mobile application
- smart cards and USB tokens
Offline mode
To improve fault tolerance, Windows Logon can create a local cache on the user computer. Such a cache contains authentication data and is used when there is no connection to the server infrastructure (the offline mode), for example due to a connection loss or during a business trip.
The lifetime of the local cache can be limited by a number of days or a calendar date. The cache is created only for the users for whom this is explicitly allowed by the Axidian Access administrator. The Windows Data Protection API technology is used to protect the local data.
Managing Active Directory user passwords
Axidian Access does not replace the standard Active Directory authentication system, but automates the management of user passwords. In such a configuration, password authentication becomes an internal mechanism used only at the software level.
The Axidian Access administrator can configure the system so that at the moment the first authenticator is registered for a user, their password is automatically changed to a random value that is disclosed neither to the user nor to the system administrator. Thus, access to the domain becomes possible only with Windows Logon. Subsequently, the user password is changed automatically, either at the request of the operating system or on a specified schedule.