Secure Windows Login: Passwordless & Phishing-Resistant

Effortless authentication for desktops, VDI, and privileged accounts, replacing traditional passwords, Windows Hello, and smart cards.

Download Datasheet

Tired of password complexity and security risks on Windows?

Passwords are a constant source of frustration and a major security vulnerability. Remembering complex passwords and frequent resets hinder productivity, while the risk of various attacks can compromise your organisation’s security. While Windows Hello offers biometric options, its security is inherently tied to the individual Windows device. If that device is compromised, the locally stored biometric data could potentially be at risk.

Introducing Idenprotect for Windows: Simple, Secure Access

Idenprotect for Windows offers a straightforward and highly secure solution for passwordless access to your Windows environment. By leveraging the biometric authentication capabilities of Idenprotect Passport on users’ mobile devices, we eliminate the need for passwords and provide a true alternative to Windows Hello without the associated complexities or hardware dependencies.

Key Features

Passwordless Windows Login

Secure and fast login to Windows desktops and servers without ever needing a password.

Authentication

Eliminates the primary attack vector for credential theft.

Secure offline access

Reliable login even without a network connection.

VDI/RDP Support

Seamless passwordless access in virtualised environments.

Log On As Support

Secure and auditable privileged access management.

Centralised management

Easy deployment and policy control through the Idenprotect management console.

Biometric authentication

Leverages the secure biometrics (fingerprint, face) on users’ mobile devices via Idenprotect Passport.

Out-of-Band authentication

Enhances security by using a separate device for verification.

Benefits of Idenprotect for Windows

  • Enhanced Security: Significantly reduces the risk of breaches caused by weak or stolen passwords and phishing attacks.

  • Improved user experience: Simplifies the login process, increasing user satisfaction and productivity.

  • Reduced IT costs: Minimises password-related support requests and, as part of a full integration with your existing Joiners, Movers, Leavers (JML) processes, can help simplify user onboarding and offboarding by eliminating the need to issue or manage passwords.

  • Simplified compliance: Helps meet security and data protection regulations.

  • Greater flexibility: Provides a consistent and secure access method across various Windows environments.

  • Cost-Effective alternative: Offers a streamlined solution without the need for specific hardware authenticators for every user.

How Idenprotect for Windows works

  • User attempts to log in to their Windows device.
  • Idenprotect for Windows, acting as a credential provider, initiates an authentication request.
  • A notification is sent to the user’s enrolled mobile device with Idenprotect Passport.
  • The user securely verifies their identity using their device’s biometrics.
  • Idenprotect for Windows receives confirmation and grants access to the Windows device.
  • For offline access, a secure, time-based one-time passcode (OTP) generated by Idenprotect Passport can be used.
  • For VDI/RDP, the process is similar, ensuring secure access to virtual sessions.
  • For “Log On As”, authorised users authenticate via Idenprotect Passport to gain elevated privileges for specific tasks.

Use Cases

  • Securing Enterprise Desktops and Laptops: Protect your organisation’s endpoints from unauthorised access by replacing vulnerable passwords with phishing-resistant biometric authentication, significantly reducing the risk of data breaches originating from compromised employee devices.

  • Enhanced Security and Offline Access: Strengthens Windows security, including remote desktop access, by ensuring only verified users log in. Offers offline authentication for access even without a network connection.

  • Streamlining VDI access: Simplify and secure login to virtual desktops, improving the user experience for virtualised environments by offering a consistent and passwordless authentication method that eliminates the friction often associated with VDI logins.

  • Managing Privileged Access: Securely grant and audit administrative access for critical tasks by requiring strong biometric authentication via Idenprotect for Windows, providing a more robust and auditable method than traditional password-based privilege elevation.

  • Flexible Alternative to Windows Hello: Offers versatile authentication for Windows, using Idenprotect Passport on smartphones. Provides consistent, strong authentication across your Windows estate, without tying users to specific machines.

Technical Specifications

Supported Operating Systems
Windows 10 (all supported versions), Windows 11 (all supported versions), Windows Server 2016, Windows Server 2019, Windows Server 2022.

Authentication Method
Idenprotect Passport mobile application leveraging device-level biometric authentication (fingerprint and facial recognition, where available on the mobile device).

Offline Access
Secure, time-based One-Time Passcode (OTP) generation within the Idenprotect Passport application for secure login when network connectivity is unavailable.

Integration
Custom Credential Provider seamlessly integrates with the Windows authentication subsystem, providing a native Windows login experience.

Management
Centralised management console accessible via a web browser, enabling administrators to easily enrol users, manage policies, and monitor access events.

Directory Services
Compatible with Active Directory (AD) and other LDAP-based directory services for streamlined user management and integration with existing identity infrastructure.

Security Protocols
Utilises Public Key Infrastructure (PKI) for secure communication and end-to-end encryption of authentication data between the Windows client and the Idenprotect backend.

Mobile Application Requirements
Idenprotect Passport application compatible with iOS (version 13 or later) and Android (version 7.0 or later).

Deployment Options
Flexible deployment options including cloud-based Idenprotect backend or on-premises deployment to suit various organisational requirements and security policies.

Logging and Reporting
Comprehensive logging of all authentication attempts, successful logins, and access events, with options for exporting logs for integration with SIEM (Security Information and Event Management) systems.

Multi-Factor Authentication (MFA) Capabilities
While providing passwordless access, the solution inherently leverages two factors: “something you have” (the user’s enrolled mobile device) and “something you are” (the user’s biometrics).

API Integration
RESTful APIs available for integration with other security and identity management platforms.

Security and compliance

Phishing Resistance
Eliminates password-based attacks, the most common entry point for cyber threats, by removing the reliance on easily compromised text-based credentials.

Out-of-Band Authentication
Adds a crucial layer of security by verifying user identity through a separate, trusted device (the user’s mobile phone), making it significantly harder for attackers to gain unauthorised access even if a Windows device is compromised.

Strong Biometric Authentication
Leverages the inherent security of device-level biometrics such as fingerprint and facial recognition, providing a user-friendly yet highly secure method for verifying identity before granting access to Windows.

PKI Encryption
Ensures the integrity and confidentiality of authentication credentials and data transmitted during the login process through the use of robust Public Key Infrastructure (PKI) encryption protocols.

Audit Logging
Provides comprehensive and detailed logs of all login attempts and access events, enabling organisations to effectively monitor activity, identify potential security incidents, and maintain compliance records.

Alignment with Compliance Standards
Furthermore, our solution aligns with key compliance standards such as NIST SP-800 and PCI DSS v4.0 by utilising the secure chips in today’s smartphones combined with built-in biometrics to provide a secure yet user-friendly approach to authentication.

Trusted by organisations worldwide

"Improved security and user experience, saving $50,000 per year and 2.5 days per employee"

IT Manager, Prominent Health Insurer in Saudi Arabia

"Streamlined secure access to a document management system for 500 staff members, enhancing security and user experience."

Head of Enterprise Business Systems, Government-Backed IT Services Provider

"Phishing-resistant, passwordless access to corporate data in a hybrid environment, improving user experience and security posture."

Head of Mobile Security, International Investment and Retail Bank

"Enhanced security and streamlined IT operations with a secure enterprise browser, mitigating phishing and password risks."

IT Security Manager, Leading International Investment and Retail Bank

Ready to secure your Windows environment with Passwordless Access?

See Idenprotect for Windows in action and discover how it can revolutionise your security.

Request a Demo

Get in touch with our team to discuss your specific needs and receive a tailored quote.

Contact Us