Enroll a one-time password (OTP) method so the user can complete offline multifactor authentication with a time-based one-time password (TOTP).
Note:The user must perform this procedure during an active Windows Authentication Client sign-in session while the device has an active network connection.
Requirements
- The WAC offline policy assigned to the user in RapidIdentity
- A Windows machine with TPM 2.0 enabled
- An authenticator app, such as the RapidIdentity app, Microsoft Authenticator, or Google Authenticator
The TOTP secret is stored in encrypted form on the Windows computer, and the authenticator app generates valid codes without a network connection. At the next offline sign-in, the Windows Authentication Client prompts the user for the one-time password and the user's password.
To re-enroll the authentication method after resetting the mobile device or the TOTP setup, click . Resetting disconnects the authentication method from the authenticator app, and the user enrolls the authentication method again.