Skip to main content
Applies to Windows Clients only.
One-time passwords add an extra layer of protection to Windows Client logins by requiring a user to request (and enter) an additional password before they can access the computer. A designated Approver processes the request, or - if configured - the password is generated and emailed automatically without requiring approval.
The Enable secondary user authentication on login and Allow the use of one-time passwords options cannot be used together. Neither works correctly if both checkboxes are selected. See Secondary user authentication for the alternative.

Enable one-time passwords

1

Open the Client or Client Group

Log in to the Management Tool as a user with the Client Configuration Management permission. Click Clients, then find the Client or Client group to configure and click its name.
2

Allow one-time passwords

On the Editing Client (or Editing Client Group) page, select the Authentication Options tab, scroll to Two-Factor and Secondary Authentication, and select Allow the use of one-time passwords.
3

Select Approvers

In Users who can approve access, select every user who should be able to approve one-time password requests.
Approvers can process a request either by clicking the link in a notification email (if they have an email address on file), or on the Access Requests page’s Access Requests tab in the Management Tool. A request that isn’t processed within 30 minutes automatically expires by default - adjustable on the System Settings tab of the Configuration page.
4

Optionally enable automatic delivery

To skip Approver review entirely for certain users, select either:
  • Automatically send one-time passwords to Active Directory users - requires an email address defined on each such user’s Active Directory account.
  • Automatically send one-time passwords to internal users - requires an email address on the internal user’s User Details tab, and the Access to Endpoint via Secondary Auth. permission granted on their Client Access tab.
5

Save

Click Finish.
Authentication Options tab showing one-time password settings

The Two-Factor and Secondary Authentication section with one-time passwords enabled.

Approve or generate a one-time password

When a user requests access, the request goes to every configured Approver by email and appears on the Access Requests page’s Access Requests tab.
1

Open Access Requests

Log in to the Management Tool as a listed Approver and click Access Requests.
2

Approve the request

Click Approve next to the relevant request, optionally enter a comment, and click Confirm.
3

Password is emailed

A one-time password is generated and sent automatically to the user’s email address.

Request and log in with a one-time password

This is the end-user flow - what a user sees when they log in to a Client with one-time passwords enabled, as opposed to the admin setup or Approver-initiated generation covered above.
1

Log in to Windows normally

Locally or remotely, as usual.
2

Request a one-time password

The Client shows a pop-up asking for a one-time password. Click Request One-Time Password.
3

Provide identifying details

A second pop-up appears, depending on which automatic-delivery options are enabled:
  • Neither automatic option enabled - enter an Email address, then click Request.
  • Automatically send to Active Directory users enabled - just click Request.
  • Automatically send to internal users enabled - enter the internal Management Tool Login and Password, then click Request.
In either of the last two cases, the user can instead select I need emergency access to computer and enter an email address manually.
4

Receive the password by email

A confirmation message appears, and the one-time password arrives by email.
5

Enter the password

Back on the first pop-up (now showing the email address automatically), enter the received password.
6

Access is granted or denied

The credentials are validated against the Application Server. If the email and password match, and the password was generated for this user and this Client, access is granted - otherwise the user sees a denial message.
Once logged in, the Client records the session under <Windows account> (<email address>) in the Client Sessions list’s User Name column.
A one-time password works only once, only within the Access Request Expiration Time (default 30 minutes), and only for the Client it was requested from. If it expires or needs resending, the user can request again - but no more than once per hour for the same Client.

Secondary user authentication

An alternative, mutually exclusive login-identification method.

Client permissions

Permissions required to configure Clients and approve access.

Windows Clients

Windows Client installation and configuration.

System settings

Change the default request expiration time.