4.3 Device Authentication

You can authenticate to Windows workstation using the Device Authentication method using one of the following:

  • Using Trusted Platform Module (TPM) chip

    The TPM chip is a crypto-processor available in Windows workstation to achieve actions, such as generating, storing, and limiting the use of cryptographic keys. Device Authentication supports authentication to Windows workstation and makes use of information available in the chip to authenticate users.

  • Non-TPM mode

    In this mode, a key pair is generated in the workstation during the enrollment process that is used for further authentication on the same workstation.

    NOTE:In non-TPM mode, ensure to enroll the Device Service method using the workstation where you would perform further authentication. Enrollment on one machine and authentication on another machine is not supported.

To authenticate with the Device Authentication method, perform the following steps:

  1. Specify one of the following:

    • The TPM chip generated PIN

    • The enrolled PIN

  2. Click Next.

    If the PIN matches with the TPM chip generated PIN or enrolled PIN, the Device Authentication is successful.