Hardware key guide

IPI Authentication Service – Hardware key pilot guide

IPI Hardware Key Solution Components

IPI Enterprise Server

  • can be deployed on both Windows and Linux server

  • is deployed from source or run on Docker

  • must be deployed on the Customer's side and entered into the domain

    in order to work with AD

IPI Client (desktop application)

  • can be installed centrally, .msi

  • is designed for Windows 10-11 only

  • You can register the server address on all Сlients centrally

IPI Keys (Hardware security tokens)

  • Replaceable (IPI Key 3) or rechargeable (IPI Key 4) battery

  • Multifunctional button with different color modes

  • Bluetooth connection

Other vendor's Security Keys

  • USB, NFS, Bluetooth connection

  • Universal Second Factor Authentication on IES (FIDO/2FA)

  • Usernameless login on IES (FIDO/WebAuthn)

  • Passwordless login on IES (FIDO/WebAuthn)

If you ordered a pilot project and successfully deployed your IPI Enterprise Server, your IPI Keys with active licenses have been added to it.

Use cases

Using the IPI Key as a Security Key

Step 1

Unpack the box with the IPI Key. Take out the key.

At this stage, you don't need either a dongle or additional IPI Group software.

Step 2

Try to use the IPI Key as a U2F security key. Using IPI Key as a U2F security key for your two-factor authentication

Step 3

Try to use the IPI Key as a FIDO2 security key for Windows 10 logon. Unlock PC by Security Key

Using the full functionality of IPI Authentication Service

Step 1

In a IPI Group email, you received the server address and access. Please go to the server and add one employee. At this stage, it is enough to fill in only his or her name and leave the rest of the data blank. How to add an Employee?

Step 2

Add the IPI Key to your Employee. Assign a key to the user

Step 3

Install the IPI Client on your workstation.

If IPI staff didn't give you any special version, then use the latest stable version, which can be downloaded here.

Installation instructions are here.

Note! You can install the IPI Client version to work with internal Bluetooth or with an external IPI Dongle.

Step 4

Enter the IES address in the IPI Client. Approve the workstation on the server. How to add and approve Workstations?

Step 5 (only for working with the IPI Dongle)

Unpack the box with the IPI Key if you haven't done so previously. Take out the key and insert the dongle into the USB port.

Step 6

Follow the steps to configure the IPI Client for the Hardware Vault. First steps with IPI Client with IPI Dongle First steps with IPI Client with internal Bluetooth

Step 7

Create your first account in the IPI Client with two-factor authentication (OTP). Using IPI Key as an OTP security key for your two-factor authentication

Step 8

Add an account to an existing employee to unlock the workstation on the server. How to work with personal employee accounts?

Step 9 (only for working with the IPI Dongle)

Unlock your computer with Bluetooth Touch. Unlock PC by Bluetooth Touch (Tap-and-Go)

Step 10

Turn on the proximity unlock option for the Workstation added to the server and specify the IPI Key that can use this option. Use proximity with Workstation

Step 11

Try to unlock the workstation by proximity. Unlock PC by proximity

Last updated