Nullam dignissim, ante scelerisque the is euismod fermentum odio sem semper the is erat, a feugiat leo urna eget eros. Duis Aenean a imperdiet risus.
The customer used usernames and passwords to authenticate users accessing its air-gapped, local Active Directory-joined Microsoft Windows systems.
The customer identified the following requirements:
In response to the customer’s requirements, Ensurity implemented the XSense IdP solution within the enterprise’s on-premises data centre.
The solution incorporated ThinC-AUTH Biometric Security Keys, XSenseCPP, and the AMS Module to enable biometric FIDO2 authentication and centrally manage the complete security key inventory.
Ensurity implemented XSense IdP within the customer’s on-premises data centre.
The on-premises implementation supported the organisation’s air-gapped environment without requiring external connectivity.
The inventory of ThinC-AUTH devices was managed through the AMS Module, the life cycle management system available within XSense IdP.
The module supported:
Ensurity customised the ThinC-AUTH Biometric Security Keys according to the enterprise’s authentication and security requirements.
The keys were configured with corporate licences for use specifically with:
This configuration required users to authenticate using their registered biometrics, providing stronger user attribution and enhancing security.
The customised security keys required users to authenticate through their registered fingerprints.
This helped the organisation:
Ensurity supplied a customised software tool for enrolling user fingerprints.
The tool supported:
Fingerprint enrolment was completed as a one-time activity. The registered fingerprint settings were saved directly on the connected ThinC-AUTH device.
FIDO2 security key sign-in to Windows machines is conventionally supported in Hybrid AD and Azure AD environments.
XSenseCPP extended this functionality to air-gapped, local Active Directory-joined machines.
The solution enabled users to sign in using:
The solution enabled authorised employees to log in to different Active Directory-joined PCs within the work area and access their assigned applications.
Authentication remained linked to the employee’s domain credentials and registered biometric security key.
The implemented solution supported: