Enrolling a One-Time Password Method for Offline Access - RapidIdentity Platform Documentation

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Enroll a one-time password (OTP) method so the user can complete offline multifactor authentication with a time-based one-time password (TOTP).

Note:The user must perform this procedure during an active Windows Authentication Client sign-in session while the device has an active network connection.
Requirements
  • The WAC offline policy assigned to the user in RapidIdentity
  • A Windows machine with TPM 2.0 enabled
  • An authenticator app, such as the RapidIdentity app, Microsoft Authenticator, or Google Authenticator
  1. In the RapidIdentity Offline Enrollment Manager, click TOTP.
  2. Add the secret to an authenticator app using one of the following methods:
    1. Scan the QR code with the authenticator app.
    2. If the QR code cannot be scanned, enter the displayed code in the authenticator app manually.
  3. In the One-time code field, enter the code generated by the authenticator app.
  4. Click Verify.

    The system validates the code against the stored secret to complete enrollment.

The TOTP secret is stored in encrypted form on the Windows computer, and the authenticator app generates valid codes without a network connection. At the next offline sign-in, the Windows Authentication Client prompts the user for the one-time password and the user's password.

To re-enroll the authentication method after resetting the mobile device or the TOTP setup, click TOTP > Reset TOTP. Resetting disconnects the authentication method from the authenticator app, and the user enrolls the authentication method again.