Active Directory
Last updated
Last updated
This guide explains how to configure passwordless login to a Windows workstation joined to an Active Directory (AD) domain using Microsoft Virtual Smart Card technology in combination with the Hideez IdentityCloud and the Hideez Authenticator mobile app. With this setup, users can log in to their domain accounts without entering a password. The domain password is updated automatically and does not need to be changed manually.
The user scans a QR code on the lock screen of the workstation using the Hideez Authenticator mobile app.
The user authenticates in the app using biometrics or a PIN.
The user selects their account.
The workstation is unlocked — no password input required.
To configure passwordless login, you will need:
Admin account in Hideez Identity Cloud.
Admin or user account in Active Directory.
.
.
.
.
.
Workstation Requirements:
Windows 10 or 11
TPM 2.0 is supported and enabled
The device is joined to the on-premises Active Directory domain
A virtual smart card is created on the workstation using the TPM module.
Smart card credentials are generated and securely transferred to the user's smartphone.
At the login screen, the user scans a QR code.
The smartphone sends the smart card credentials to the PC through a secure channel.
The workstation is unlocked without the user entering a password.
To set up the environment for passwordless workstation logon, you need to configure both the Active Directory Certification Authority and the Hideez Identity Cloud server. For detailed instructions, please refer to the links below: