Nullam dignissim, ante scelerisque the is euismod fermentum odio sem semper the is erat, a feugiat leo urna eget eros. Duis Aenean a imperdiet risus.

The Challenge

The bank wanted to:

Eliminate vulnerabilities associated with single-factor authentication.
Prevent password and credential sharing.
Discard soft authenticators and implement attributable security keys.
Establish centralised key management across different geographic locations.
Lock each security key to the respective bank user’s Azure AD account.

Required Key Management Functionalities

The bank also required the following key management capabilities:

PIN control
Fingerprint enrolment within a secure environment
Restrictions on security key resets
Restrictions on new self-enrolments
Key reassignment
Key reactivation
Key locking
Centralised management of all key-related functions

The Ensurity Solution

Ensurity provided customised FIDO2 biometric security keys along with its Life Cycle Management Software to fulfil the bank’s authentication, security, and centralised management requirements.

The solution consisted of three primary components:

01

ThinC-AUTH Biometric Security Keys

02

Life Cycle Management Software

03

Customised Security Key Functionalities

ThinC-AUTH Biometric Security Keys
01

ThinC-AUTH Biometric Security Keys

Ensurity integrated its ThinC-AUTH biometric FIDO2 security keys with the bank’s Hybrid AD environment, providing Single Sign-On access to its applications.

The solution enables users to access applications through centrally managed biometric security keys, eliminating the need for conventional passwords.

This Approach Helps Mitigate Risks Associated With:

  • Phishing attacks
  • Unauthorised credential sharing
  • Password-based authentication
  • Misuse of user credentials
02

Life Cycle Management Software

To streamline the centralised deployment and management of hardware security keys across different locations, Ensurity implemented its Asset Management System within the bank’s data centre.

The system operates with zero external access.

Asset Management System Capabilities

The Asset Management System provides the following functionalities:

  • Easy inventory management of ThinC-AUTH biometric security keys
  • User identity synchronisation with the bank’s Azure AD
  • Log in to the AMS portal using Azure AD-assigned MFA
  • Role assignment for: Administrators, Service users and Generic users
  • Automated emails regarding security key assignment status
  • A controlled environment for registering fingerprints on biometric security keys
  • Flexibility to configure between one and five fingerprints
  • Remote resetting of ThinC-AUTH keys to remove the fingerprint data of previous users through the AMS Agent tool
Enterprise Identity And Access Management
Enterprise Identity And Access Management
03

Customised Security Key Functionalities

Ensurity customised the security keys to provide the following functionalities:

  • FIDO2 authentication for WebAuthn-enabled applications
  • Compatibility with Windows 10, Version 1903 and later releases
  • Dynamically generated PIN for every security key during enrolment
  • Disabled PIN fallback to prevent wilful misuse of the security key
  • Restriction of each key to a single Microsoft account
  • Prevention of users from adding a second Microsoft account
  • Prevention of security key resets through the Windows tool
  • Configurable limits for the maximum number of fingerprints
  • Remote security key reset through Ensurity’s Asset Management System portal

The Outcome

Ensurity fulfilled the bank’s requirements by delivering a complete security key life cycle solution through its Asset Management System and customised FIDO2 biometric security keys.

Using the solution, the bank’s users could securely access their applications through centrally managed FIDO2 biometric security keys.

Key Outcomes

Passwordless access to business applications

Reduced phishing and credential-sharing risks

Centralised management of security keys across locations

Controlled fingerprint enrolment

Secure reassignment and resetting of security keys

Integration with the bank’s Hybrid AD and Azure AD environments

Greater administrative control over the complete security key life cycle

Enterprise Identity And Access Management