Basic concepts of Digipass Authentication for Windows Logon

Prev Next

Digipass Authentication for Windows Logon enables users to log on to Windows with a Digipass authenticator. It integrates seamlessly with the existing Windows logon system. The user ID is entered together with a one-time password (OTP) generated by the Digipass authenticator. The existing Windows static password is released and passed to the Windows logon system. Digipass Authentication for Windows Logon securely stores the Windows static password using strong encryption.

A Digipass authenticator is a device that generates one-time passwords. It can be provided to individuals of an organization who log on to the system with a one-time password (OTP). The user generates the OTP with the authenticator and uses the OTP instead of, or along with, a static password when logging on.

Mode of operation

Digipass Authentication for Windows Logon (DAWL) is installed on the client PC, where it collects the authentication credentials entered by the user. Digipass Authentication for Windows Logon performs a DNS lookup to locate the correct instance of OneSpan Authentication Server and delegates the validation of the one-time password (OTP) to OneSpan Authentication Server.

During advanced installation, OneSpan Authentication Server automatically registers its location with the DNS server. With this, the Digipass Authentication for Windows Logon client can automatically locate the authentication server.

OneSpan Authentication Server receives input from the Digipass Authentication for Windows Logon client, processes the authentication request, and sends the authentication request results back to the client PC.

Digipass Authentication for Windows Logon architecture – Overview

To install Digipass Authentication for Windows Logon with OneSpan Authentication Server, both the OneSpan Authentication Server license as well as the Digipass Authentication for Windows Logon client license are required (see Licensing requirements).

Components or features described in this document may need to be configured to meet the standards of the  General Data Protection Regulation (GDPR). If your organization is collecting or in any capacity processing data on citizens of a European Union country, your organization is subject to the GDPR.

For more information about GDPR, refer to the OneSpan Authentication Server GDPR Compliance Guide.

Components

Digipass Authentication for Windows Logon consists of client and server components. The client components are installed on the client PC, the server components are part of OneSpan Authentication Server.

Client components

Digipass Authentication for Windows Logon is installed on the client PC, together with the tray application, Digipass Authentication for Windows Logon Tray Agent.

Server components

The Digipass Authentication for Windows Logon server components are:

  • OneSpan Authentication Server

  • OneSpan Authentication Server Administration Web Interface

  • Audit Viewer

  • Password Synchronization Manager (PSM)

For more information about the server components and how they interact, refer to the OneSpan Authentication Server Product Guide.