Configuring Imprivata Secure Walk Away

 

Imprivata Secure Walk Away enables automatic walk–away security based on the proximity of your users' mobile phones. Imprivata Enterprise Access Management monitors enrolled phones and:

  • Locks the endpoint when the phone is no longer detected.

  • Optionally, unlocks the endpoint when the phone is detected during a grace period.

Secure Walk Away can be used in combination with, and falls back to, existing keyboard and mouse inactivity timers.

Requirements

Review the following requirements:

Supported User Workflows

Monitoring a user's presence helps to provide for a better balance between security and user convenience. You can:

  • Increase inactivity timeouts because you know the user is nearby.

  • Fallback to existing inactivity timeouts for a user who does not have their phone or if the phone cannot be detected.

  • Optionally, automatically unlock the workstation when the user returns to the workstation.

The following factors can help you decide whether automatically unlocking the workstation is right for the environment:

  • The physical location of the workstations.

  • The number of clinicians that use the workstation during a particular time.

Prepare the Environment

Complete the following to prepare the environment for Secure Walk Away.

Configure Imprivata Secure Walk Away

What to Expect on the Workstation

The following sections detail what users can expect to see on the workstation.

Reporting

You can use the Computer Peripheral Usage report to identify where BLE enabled devices have been deployed in your enterprise. This report identifies:

  • Endpoints to which a BLE device has been plugged in.

  • The model and vendor of the device.

  • The version of the firmware installed on the device.

To run the report:

  1. In the Imprivata Admin Console, click Reports > Add new report.

  2. Under the Platform column, click Computer Peripheral Usage.

  3. Specify a date range, and click Run.

    The date range indicates when the BLE device was plugged into the endpoint.

    For example, a report with a date range of Today, will not include an endpoint where the BLE device was plugged in two days ago.

Troubleshooting

Symptom

When I return to my workstation, the Imprivata agent does not recognize my phone. The BLE icon is gray.

Solution

This may be the result of:

  • Closing Imprivata ID.

  • (iOS only) The iPhone restarting.

Opening Imprivata ID after an iPhone restarts resolves the issue. However, the time it takes to recognize the phone varies.

During this time, log in as you normally would.

Symptom

When I return to my workstation, there is an X through the BLE icon on the lock screen.

Solution

  1. Is the BLE–enabled hardware plugged into the workstation?

  2. This may be indicative of a problem with Windows recognizing the BLE hardware.

    Although Imprivata Secure Walk Away is disabled, you can login as normal to continue working.