Passwordless Authentication with Device-Bound Passkey
Imprivata Enterprise Access Management supports passwordless authentication for Desktop Authentication with a device-bound passkey.
Best Practices
-
Only enable device-bound passkeys at single user computers (Type 1) .
-
To make the enrollments 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway:
-
Imprivata ID or device-bound passkey
-
Imprivata PIN or device-bound passkey
-
Security Key or Imprivata PIN or Proximity Card or Device-bound passkey
-
Enrollment Limits
When needed, you can set enrollment limits for device-bound passkeys at the user and computer policy levels. A new enrollment can only be made if the enrollment meets both the user and computer policy limits:
-
Unlimited enrollments — a user can enroll on multiple computers, but never more than one passkey on the same computer.
-
Limit = 1 — Exclusive and non-replaceable. If the user already has a passkey enrolled anywhere, a new enrollment is rejected. To enroll a new passkey, the admin must manually delete the existing passkey in the user or computer policy page. See Deleting Enrollment.
-
Limit = 2-99 — Automatic "first in, first out" replacement. When the limit would be exceeded, the user's oldest/least-recently-used passkey is removed to make room for the new enrollment.
These limits do not apply to external FIDO2 security keys.
Enable in User Policy
-
In the Imprivata Admin Console, go to Users > User policies.
-
Go to Authentication > Desktop Access authentication
-
Select Imprivata PIN and Device-bound passkey.
-
To make the enrollments 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway.
-
Go to Authentication method options > Security key.
Specify a enrollment cap and grace period, if needed.
-
Click Save.
Enable in Computer Policy
-
In the Imprivata Admin Console, go to Computers > Computer policies.
-
Select a computer policy to configure.
-
Go to General > Authentication and select Enable Device-bound passkey.
Specify a enrollment cap if needed.
-
Click Save.
Expected Workflow
-
To enroll the device-bound passkey, the user logs into the desktop or the enrollment utility with two authentication methods.
The device-bound passkey is now enrolled.
-
The next time the user logs into the desktop, the user will only need to complete their primary factor of authentication. The device-bound passkey is the second factor and is completed 'silently' for them.
Deleting Enrollment
The device-bound passkey enrollment can be deleted from the user or computer page in the Imprivata Admin Console.
Deleting on the User Page
-
In the Imprivata Admin Console, go to Users > Users.
-
Select the user whose enrollment you want to delete.
-
Go to Security Key > Device-bound passkey.
Enrolled passkeys are listed by hostname and enrollment date and time.
-
Select the enrollment to delete.
-
Click Save.
Deleting on the Computer Page
-
In the Imprivata Admin Console, go to Computers > Computers.
-
Select the computer where the user enrolled.
-
Go to Device-bound passkeys.
Enrolled users are listed by username and enrollment date and time.
-
Select the enrollment to delete.
-
Click Save.