Protect the client installation

Prev Next

You can protect the Digipass Authentication for Windows Logon client installation from being removed to increase security and environment integrity. This supports locked down environments where you need to ensure that software packages cannot be removed by unauthorized users.

The installation protection can be configured either via Windows Registry or via Group Policy. By default, it is disabled.

The values configured via Group Policy take precedence over values configured via Windows Registry.

Configuration via Windows Registry

The installation protection can be configured via the following Windows Registry key:

[HKLM\SOFTWARE\OneSpan\Digipass Authentication for Windows Logon\Common\Installer]

  • ProtectUninstall (REG_DWORD)

    If you set this value to 1, uninstallation is allowed only if the user who attempts to remove Digipass Authentication for Windows Logon is a member of the Active Directory group specified by the ADGroupName value.

    Default value: 0

  • ADGroupName (REG_SZ)

    Only users who are direct member of this user group are allowed to uninstall the client software. Otherwise, the uninstall is blocked and Windows installer returns an error. You can specify the name of one Global user group in Active Directory only.

    Default value: Domain Admins

The Digipass Authentication for Window Logon setup writes this Registry key if you install it with the PROTECTUNINSTALL property (see Install Digipass Authentication for Windows Logon).

Configuration via Group Policy

The installation protection can be configured using the following options in the Group Policy (Computer Configuration > Policies > Administrative Templates > OneSpan > Digipass Authentication for Windows Logon > Authentication and Security > Installer):

  • Restrict uninstallation. If you set this policy setting to Enabled, uninstallation is allowed only if the user who attempts to remove Digipass Authentication for Windows Logon is a member of the Active Directory group specified by the Required AD group name option.

    Default value: Disabled

  • Required AD group name. Only users who are direct member of this user group are allowed to uninstall the client software. Otherwise, the uninstall is blocked and Windows installer returns an error. You can specify the name of one Global user group in Active Directory only.

    Default value: Domain Admins

When installation protection is enabled, the Configuration Center shows a respective note on the Version page.