---
title: Prerequisites
description: Before beginning the installation you must:
component: enterprise-connect
version: latest
page_id: enterprise-connect:windows-radius-proxy-3.0.2:prereqs
canonical_url: https://docs.pingidentity.com/enterprise-connect/latest/windows-radius-proxy-3.0.2/prereqs.html
section_ids:
  windows_proxy_supported_environments: Supported environments
---

# Prerequisites

Before beginning the installation you must:

* Have administrative privileges on the target Windows machine.

* Download the Enterprise Connect Windows Workstation Authentication installation file from [Backstage](https://backstage.pingidentity.com/downloads/browse/ig/all/productId:enterprise-connect).

  |   |                                                                          |
  | - | ------------------------------------------------------------------------ |
  |   | You must have a Backstage account and be logged in to view the download. |

* Create a service account user for the Enterprise Connect Windows RADIUS proxy to run as. The minimum account privileges this user needs are:

  * Enable *Log on as a service*. For more information, learn more in Microsoft's [documentation](https://docs.microsoft.com/en-us/system-center/scsm/enable-service-log-on-sm?view=sc-sm-2022).

  * Write permission to C:\windows\system32 to have access to create the `logs` folder.

  * Write permission to C:\Windows\System32\logs folder.

* Pre-configure journeys and services, as described in [Create authentication journey(s)](../workstation-windows-guide-3.7.2.7293/creating-authentication-journey.html).

* Ensure all usernames (profiles/accounts) match from *Windows (or the authoritative source) > Ping* and vice versa.

  * Set up a connector from Ping Identity to the datastore (for example, AD) and sync the data.

* For [push](../workstation-windows-guide-3.7.2.7293/creating-authentication-journey.html#example_push_journey) and [OTP (TOTP/OATH)](../workstation-windows-guide-3.7.2.7293/creating-authentication-journey.html#example_otp_journey) authenticator methods, users pre-register in the appropriate journeys.

  |   |                                                                                                           |
  | - | --------------------------------------------------------------------------------------------------------- |
  |   | It's crucial for users to pre-register. Otherwise, these MFA methods won't work through the RADIUS proxy. |

  |   |                                                                                                                                                                                                                                                                            |
  | - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  |   | Your RADIUS client **must** support the exchange of the TOTPs from Ping Identity journey > RADIUS proxy > RADIUS client and conversely to work. This includes handling *challenge-response* flows. If your client can't handle the calls, use the **push** method instead. |

* Users install the PingID mobile app to their smartphone. Learn more in [PingID mobile app help center](https://docs.pingidentity.com/pingid-user-guide/pid_mobile_app/ma_pidma_help_center_landing.html).

* For high availability or disaster recovery, you should deploy the necessary amount of Enterprise Connect Windows Workstation Authentication behind load balancers. Additionally, only **one instance per machine is allowed**.

## Supported environments

Enterprise Connect Windows Workstation Authentication can only be installed on the following operating systems:

* Windows 10

* Windows 11

* Windows Server 2016

* Windows Server 2019

* Windows Server 2022

|   |                                                        |
| - | ------------------------------------------------------ |
|   | Windows 8.1 and Windows Server 2012 are not supported. |
