Passwordless Windows Logon
The Passwordless Windows Logon feature is MFA based on X.509 (PKI) standards, but, without the inherent complexities of a typical PKI solution. Achieving enterprise-wide passwordless authentication is a journey and Passwordless Windows Logon is the first step in that direction. It helps enterprises in:
- Eliminating the need of passwords for machine access and beyond, thereby enhancing the overall security posture of enterprises and augmenting the end user experience by minimizing user friction.
- Reducing operational expenses due to minimized help desk calls for password resets.
- Providing superlative end-user experience to their employee, thereby improving their overall productivity.
- Onboarding the enterprise-wide passwordless and modern authentication journey.
System requirements
To use the Passwordless Windows Logon feature, the following requirements must be met:
Client-side requirements
Supported authentication tokens
- All OTP-based authenticators currently supported by SafeNet Trusted Access (STA). For example, MobilePASS+, GrIDsure, and Hardware tokens.
- The Windows machines must be enabled with TPM 2.0.
Server-side requirements
Communication protocols
- HTTPS (TLS 1.2 and above)
Operating systems
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022
- Windows Server 2025
Software prerequisites
- SafeNet Authentication Service (SAS) PCE v3.20 or above
- Microsoft Active Directory Certification Services (AD CS) with NDES service must be configured with a valid Root CA on the same domain network.
- Microsoft IIS 10, to host SafeNet SCEP Adaptor for secured management of certificate signing requests.
- The following IIS components must be installed and enabled:
- IIS 6 Management Compatibility Role Service (and its sub-components)
- ISAPI filter role
- SafeNet Access Exchange (SAE) must be configured with HTTPS communication protocol.
Note
For passwordless enrollment, both the client-side and server-side components must be in the corporate network.
Limitations
Following are the limitations of the passwordless solution in this release:
- A maximum of eight users is supported on a shared machine.