Version 3.10 (September 2026)

Prev Next

New features and enhancements

Client installation protection

You can now protect the Digipass Authentication for Windows Logon client installation from being removed to increase security and environment integrity. This supports locked down environments where you need to ensure that software packages cannot be removed by unauthorized users.

The new installation protection can be configured either via Windows Registry or via Group Policy. By default, it is disabled.

Supported platforms, database management systems, and other third-party products

Software libraries

The software library lists are not exhaustive and include the most significant and security-relevant updates only. CVE references are provided for informational purposes only and do not imply that the corresponding vulnerabilities were exploitable in the product. For a complete overview, refer to the third-party dependency files included with the installed product.

This version now includes the following (updated) third-party libraries:

Upgrade paths

Digipass Authentication for Windows Logon supports upgrading from version 3.1 or later to version 3.10 on the currently supported Windows operating systems.

Fixes and other updates

Issue OAS-35990: Credential provider filtering not fully Microsoft-compliant

Description: According to the Microsoft specification for credential provider filters, filtering must not be applied when the usage scenario of a credential provider is set to credential UI (CPUS_CREDUI) and the according usage scenario flags request the credential provider to return the username and password in plain text (CREDUIWIN_GENERIC).

If you enable credential provider filtering, the Credential Provider does not check for this specific scenario combination before applying the filtering logic. This can remove valid credential providers from an application’s credential prompt and, in the worst case, break third-party applications that rely on the Windows Credential UI to collect credentials.

Affects: Digipass Authentication for Windows Logon 3.5–3.9

Status: This issue has been fixed. The Credential Provider now correctly skips filtering in this scenario, ensuring full compliance with Microsoft filtering rules.

Issue OAS-33926 (Support case CS0214621): Specific DNS configuration can cause application crashes (Authentication Provider)

Description: If the Connection Settings > Enable DNS lookup option is enabled, the Authentication Provider can terminate unexpectedly due to a division-by-zero error. This issue occurs only in environments where multiple SRV DNS records are configured for OneSpan Authentication Server and, within at least one priority level, all matching records (at least two) have a weight of 0.

Affects: Digipass Authentication for Windows Logon 3.5–3.9

Status: This issue has been fixed.

Deprecated components and features

Support for 32-bit Windows platforms (Deprecated)

Support for Digipass Authentication for Windows Logon on 32-bit platforms is considered deprecated and will be removed in a future release (currently planned for 3.11).

If you are using Digipass Authentication for Windows Logon on 32-bit Windows clients, we strongly recommend migrating to a 64-bit platform to allow future upgrades.

Supported platforms and other third-party products

This version no longer supports the following products:

Operating systems

  • Windows 10 Anniversary Edition (version 1607 LTSB)

  • Windows Server 2016

Known issues

Issue OAS-20833: Windows logon process gets unresponsive when DNS lookup is enabled but authentication server is unreachable (Credential Provider)

Description: If Connection Settings > Enable DNS lookup is enabled and the OneSpan Authentication Server instance becomes unreachable (for example, because of network connectivity issues or request timeouts), the Windows logon process can get unresponsive and hang indefinitely. This issue is caused by a flaw in the SOAP component initialization, where DNS resolution may block for a long time before timing out. If a user enters credentials and start an authentication process before the initialization completes, the authentication thread can end up waiting indefinitely for the connection thread to terminate, resulting in an unresponsive logon process.

Affects: Digipass Authentication for Windows Logon 3.5 and later

Status: No fix or workaround. If you experience this issue a lot, disable DNS lookup and configure a fixed IP address for the OneSpan Authentication Server instance instead.