PingID Administration Guide

Installing passwordless Windows Login integration on client computers

You can install the integration for passwordless Windows login on your users' computers with the command-line interface that is provided or with the UI-based installation.

Requirements

  • To use the passwordless Windows login feature, users' computers must be running Windows 10 (64-bit) or Windows 11, and must support TPM 2.0.

    If you have set the Resident Key option to Required for FIDO2 security keys, users do not require TPM on their computer in order to use the passwordless login, provided that they paired their keys after the setting was changed to Required. For more information on the Resident Key option, see (Legacy) Configuring the FIDO2 security key for PingID. Since TPM 2.0 provides a higher degree of security, the passwordless login for Windows will always use TPM for storage if the relevant computer has the necessary support.

  • The first time that a user carries out passwordless Windows login, they need to be online and connected to the organizational network because certificate enrollment requires a connection to Active Directory. Afterwards, there is no need for a connection to the network, and authentication can be carried out online or offline (for as long as the certificate is valid).

Installing passwordless Windows Login integration on client computers (UI)

You can install the integration for passwordless Windows Login on your users' computers with the UI-based installation described in this topic.

Steps

  1. Run the provided executable, and when the welcome screen is displayed, click Next.

    Win Login Passwordless - UI-based installation - initial screen
  2. Accept the license agreement and click Next.

    Win Login Passwordless - UI-based installation - license agreement
  3. The settings that must be entered on the Passwordless Sign-on Settings screen should be copied from the Configuration tab of the application you created for Windows Login - Passwordless in PingOne. If your organization uses a proxy, click Configure Proxy. Otherwise, click Next.

    Win Login Passwordless - UI-based installation - application settings
  4. If you clicked Configure Proxy in the previous step, enter the proxy information, click Apply, and when you are returned to the Passwordless Sign-on Settings screen, click Next.

    Win Login Passwordless - UI-based installation - proxy configuration
  5. When the Ready to Install screen is displayed, click Install to start the installation.

    Win Login Passwordless - UI-based installation - final screen