Administrator Guide

Table Of Contents
Steps
1. Tap the proximity card. The card enrollment page is displayed.
2. Enter the credentials and click OK.
Proximity card is enrolled successfully.
Use smart card as proximity card
You can use a smart card as a proximity card to authenticate the user. When you tap the smart card on the smart card reader,
the Imprivata agent uses the smart card's unique serial number as the Unique ID (UID) of the proximity card.
About this task
This section describes how to use a smart card as a proximity card.
Steps
1. Log in to the OneSign Administrator console.
2. Go to the Policies page and click Computer Policy.
3. In the Smart card readers section, select the Treat smart card authentications as proximity card authentications
check box.
Next steps
To authenticate the user using a proximity card, connect a supported reader to the thin client. Before you tap the card, ensure
that your card is already enrolled to the user. When you tap your card on the reader, the thin client authenticates the user and
starts the VDI connection.
Imprivata Bio-metric Single Sign-On
Fingerprint identification feature is highly reliable, and cannot be replicated, altered, or misappropriated.
The prerequisites of OneSign server are:
Imprivata v4.9 or later appliance version is needed that supports the WebAPI v5 and later versions.
Fingerprint identification license is required.
Fingerprint reader device is required. ET710 (PID 147e VID 2016) and ET700 (PID 147e VID 3001) are the supported devices.
Supported user scenarios
Signing in or unlocking the ThinOS devices using the Fingerprint authentication.
Configure the OneSign server on ThinOS, and then connect the Fingerprint reader device.
The ThinOS Fingerprint window is displayed automatically after the OneSign server is initialized.
Fingerprint authentication works on the ThinOS unlock window.
Unlocking the Virtual Desktop using the Fingerprint authentication.
Enable the Imprivata Virtual Channel option from the ThinOS Global Connection settings.
When you lock the virtual desktop in the session, the Fingerprint window is displayed automatically.
Managing Fingerprints on a virtual desktop.
Legend Fingerprint Management is supported.
Fingerprint management with Imprivata Confirm ID enabled is not supported.
Grace period to skip second authentication factor
Grace period enables you to specify a time limit on OneSign server for logging in without the second authentication factor after
the first login session.
NOTE:
After you specify the grace period, you must first use the proximity badge, and then enter password or OneSign PIN
for the initial login.
If you use the proximity card after the time limit that you specified for grace period, the second authentication factor window is
displayed with the message Grace period expired.
58
Configuring connectivity