SafeNet Agent for Windows Logon
SafeNet Agent for Windows Logon is a lightweight software that is installed on Windows machines to augment logon security by invoking Multi-factor Authentication (MFA). It ensures that valuable resources are accessible only by authorized users. The agent also protects desktop applications and processes which use CredUI.
The use of MFA in addition to AD authentication adds another layer of security. The agent provides a secured and consistent logon experience to the end users of Windows machines.
This is a preview feature. Contact Thales Customer Support to request access to preview features.
For information about the released features, see: SafeNet Agent for Windows Logon.
Preview Release Disclaimer
Release intent: Thales preview releases are short-lived and made available to customers "On Demand", allowing them to provide feedback and explore upcoming feature/s specific to the preview release. Release caveats: - Non-production usage: Preview releases are not intended for use in production environments and Thales will not provide support for the production use of preview releases. - Limited functionality: Preview releases may have limited or restricted functionality and there are no warranties for such releases. - Support: Preview releases may be changed or discontinued. Upgrades from previous and upgrade to upcoming GA versions of the product are not supported.
Preview Release Description
v4.4.0
This preview release introduces the following features
-
Support for User Choice of Authenticator (UCA): UCA allows users to select from their available authentication methods during Windows logon. When a user signs in, they are presented with a list of the authentication methods they have enrolled in SafeNet Authentication Service Private Cloud Edition (SAS PCE). To disable UCA, set the value of the DisableUCA registry key to 0. For more information, see Registry settings.
-
Support for FIDO2 authenticators: FIDO2 (Fast IDentity Online) is a set of open standards designed to provide phishing-resistant and strong authentication. FIDO authentication in the SafeNet Agent for Windows Logon aims to eliminate passwords for online authentication, offering a more secure and user-friendly experience.
Note
FIDO support in this release is tested with Thales FIDO authenticators.
-
Support for Passwordless Windows Logon: The Passwordless Windows Logon feature is MFA based on X.509 (PKI) standards, but without the inherent complexities of a typical PKI solution. It eliminates the need for passwords for machine access, enhances the overall security posture of enterprises, and augments the end-user experience by minimizing user friction. It also reduces operational expenses due to minimized help desk calls for password resets.
-
Two registry settings, PasswordlessEnabled and PasswordlessGroup, have been added to support passwordless logon. For more details, see registry settings.
-
While authenticating with passwordless logon, ensure that you configure the registry settings.
-
-
Lock screen on FIDO USB authenticator removal: When you authenticate to your Windows system using a FIDO USB authenticator, the system locks automatically.It is an optional feature, for more details, see registry settings.
Resolved Issues
| Issue | Synopsis |
|---|---|
| SASNOI-25015 | Hardware tokens (OTP-110/eToken) appear grayed out and cannot be selected during offline authentication. |
| SASNOI-24756 | Domain Admin accounts are redirected back to the Windows sign-in screen immediately after the Welcome screen when logging in interactively via VMware vSphere Web Console with WLA Online Authentication enabled. |
| SASNOI-24746 | The Windows Logon Agent (WLA) Manager crashes when attempting to perform Manual Replenish under the Offline tab. The operation fails with an unhandled exception indicating an Autofac assembly version mismatch. |
| SASNOI-24622 | The required language files (lang-list and de.json) are installed in the Languages\Latest folder instead of the expected Languages folder. |
| SASNOI-22919 | RDP connections to AWS Windows Server 2022 intermittently display a blank screen instead of the UCA login screen, resulting in session timeouts. |
| SASNOI-22663 | Users accessing Windows Admin Shares on Windows 11 are not prompted for MFA and can authenticate with a password alone, despite MFA being enforced. |
| SASNOI-21267 | Enabling the Require trusted path for credential entry Group Policy setting caused the UAC prompt to incorrectly display MFA text during outgoing RDP sessions. |
| SASNOI-20080 | Local account autologon fails with an error when WLA v3.6.3 or above is enabled, preventing users from logging in automatically. |