Nullam dignissim, ante scelerisque the is euismod fermentum odio sem semper the is erat, a feugiat leo urna eget eros. Duis Aenean a imperdiet risus.

Customer Environment

The customer operates across multiple geographic locations and uses a Microsoft cloud environment for its business operations.

Existing Technology Environment

Operations across multiple geographic locations
Microsoft cloud environment
Microsoft Windows systems
Azure Active Directory
Enterprise applications
Shared PCs within designated work areas

The Challenge

The customer identified the following authentication and access requirements:

Enable FIDO2-based authentication for its enterprise applications.
Ensure that employees use FIDO2 security keys for secure authentication across enterprise applications.
Restrict employees from sharing passwords and authenticators.
Eliminate PIN-based authentication as an alternative to biometric authentication.
Prevent the misuse of security keys through PIN fallback.
Enable employees to use any PC within the work area to access their applications.
ThinC-AUTH Biometric Security Keys

The Ensurity Solution

In response to these requirements, Ensurity implemented its ThinC-AUTH Biometric Security Keys within the customer's Microsoft-based environment.

The security keys and supporting enrolment software were customised to enforce biometric-only authentication and eliminate password and PIN-based login methods.

Solution Implementation

01

Customised ThinC-AUTH Biometric Security Keys

Ensurity customised the ThinC-AUTH Biometric Security Keys to support the customer's authentication requirements.

This configuration required users to authenticate through their registered biometrics.

This configuration required users to authenticate through their registered biometrics.

ThinC-AUTH Biometric Security Keys
02

Elimination of PIN Fallback

The fallback PIN authentication option was disabled to prevent users from bypassing biometric verification.

Even when an incorrect fingerprint authentication attempt was made, the security key did not fall back to PIN-based authentication.

This restricted users to authenticating exclusively through their enrolled biometrics.

03

Cross-Platform Fingerprint Enrolment Tool

Ensurity developed a customised software tool for enrolling user fingerprints and disabling PIN-based authentication.

The enrolment tool supported:

  • Microsoft Windows
  • macOS
  • Linux

The configured settings were stored directly on the connected ThinC-AUTH device.

The configured settings were stored directly on the connected ThinC-AUTH device.

Cross-Platform Fingerprint Enrolment Tool
04

Passwordless Windows Sign-In

The implemented solution enabled users to log in to their Microsoft Windows systems using ThinC-AUTH Biometric Security Keys without entering their passwords.

Authentication was fully completed through the user's enrolled fingerprint.

Passwordless Windows Sign-In
05

Authentication Across Work-Area PCs

The solution enabled employees to use different PCs within their designated work areas to access their applications.

Users could securely authenticate through their assigned ThinC-AUTH Biometric Security Keys and registered biometrics instead of relying on shared or manually entered passwords.

Solution Capabilities

The implemented solution supported:

FIDO2-based authentication

Passwordless Windows sign-in

Biometric-only user authentication

Disabled PIN fallback

Fingerprint-based user verification

Prevention of password sharing

Prevention of authenticator sharing

Access to enterprise applications

Authentication across Azure AD-connected Windows systems

Cross-platform fingerprint enrolment

Storage of biometric enrolment settings directly on the security key

Employee access through different PCs within the work area

Implementation Result

Following the implementation, users could log in to their Microsoft Windows systems through ThinC-AUTH Biometric Security Keys without entering passwords.

By disabling fallback PIN authentication, the solution ensured that users authenticated only through their enrolled biometrics.