Passwordless Authentication with Device-Bound Passkey

Imprivata Enterprise Access Management supports passwordless authentication for Desktop Authentication with a device-bound passkey.

Best Practices

  • Only enable device-bound passkeys at single user computers (Type 1) .

  • To make the enrollments 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway:

    • Imprivata ID or device-bound passkey

    • Imprivata PIN or device-bound passkey

    • Security Key or Imprivata PIN or Proximity Card or Device-bound passkey

Enrollment Limits

When needed, you can set enrollment limits for device-bound passkeys at the user and computer policy levels. A new enrollment can only be made if the enrollment meets both the user and computer policy limits:

  • Unlimited enrollments — a user can enroll on multiple computers, but never more than one passkey on the same computer.

  • Limit = 1 — Exclusive and non-replaceable. If the user already has a passkey enrolled anywhere, a new enrollment is rejected. To enroll a new passkey, the admin must manually delete the existing passkey in the user or computer policy page. See Deleting Enrollment.

  • Limit = 2-99 — Automatic "first in, first out" replacement. When the limit would be exceeded, the user's oldest/least-recently-used passkey is removed to make room for the new enrollment.

These limits do not apply to external FIDO2 security keys.

Enable in User Policy

  1. In the Imprivata Admin Console, go to Users > User policies.

  2. Go to Authentication > Desktop Access authentication

  3. Select Imprivata PIN and Device-bound passkey.

  4. To make the enrollments 'invisible' to the user, select a second factor that combines device-bound passkey with a second factor they would use anyway.

  5. Go to Authentication method options > Security key.

    Specify a enrollment cap and grace period, if needed.

  6. Click Save.

Enable in Computer Policy

  1. In the Imprivata Admin Console, go to Computers > Computer policies.

  2. Select a computer policy to configure.

  3. Go to General > Authentication and select Enable Device-bound passkey.

    Specify a enrollment cap if needed.

  4. Click Save.

Expected Workflow

  1. To enroll the device-bound passkey, the user logs into the desktop or the enrollment utility with two authentication methods.

    The device-bound passkey is now enrolled.

  2. The next time the user logs into the desktop, the user will only need to complete their primary factor of authentication. The device-bound passkey is the second factor and is completed 'silently' for them.

Deleting Enrollment

The device-bound passkey enrollment can be deleted from the user or computer page in the Imprivata Admin Console.

Deleting on the User Page

  1. In the Imprivata Admin Console, go to Users > Users.

  2. Select the user whose enrollment you want to delete.

  3. Go to Security Key > Device-bound passkey.

    Enrolled passkeys are listed by hostname and enrollment date and time.

  4. Select the enrollment to delete.

  5. Click Save.

Deleting on the Computer Page

  1. In the Imprivata Admin Console, go to Computers > Computers.

  2. Select the computer where the user enrolled.

  3. Go to Device-bound passkeys.

    Enrolled users are listed by username and enrollment date and time.

  4. Select the enrollment to delete.

  5. Click Save.