Support for Credential Provider Filters and User Interface
This update provides administrators with granular control over credential providers while maintaining secure access to system configurations. The filters can enable or disable system password providers and restrict users' visibility so they can only see the Windows Authentication Client.
Administrators can configure these filters in both connected and disconnected environments, as long as the administrator has logged in to the client in connected mode once. To configure these filters, navigate to the Settings tile on the Windows sign-in screen.
Additionally, the Windows Authentication Client integrates with the Credential User Interface (UI) to provide administrators a method for validating admin credentials during the User Account Control prompt. Authentication via all Windows Authentication Client methods in the Credential UI are permitted for administrators, excluding Pictograph, QR Code, and FIDO.
Other Changes and Improvements
-
All users can now update their local password after it expires or change their password from the login window when the Windows Authentication client is in connected mode.Note:
Jamf recommends all Active Directory and local machine password policies align with existing RapidIdentity password policies to prevent unexpected errors.
-
The Windows Authentication Client now supports screen readers including Windows Narrator and Job Access with Speech (JAWS) to aid users during the login process.
-
Users can now authenticate with the Windows Authentication Client in disconnected mode using all standard authentication methods. Additionally, any RapidIdentity username can now be used as long as the user has logged in to the client in connected mode once. For more information, see Offline Access with the Windows Authentication Client.
-
Windows Authentication Client users can now sync and update passwords between Active Directory and RapidIdentity using ID Hub.
Resolved Issues
-
Fixed: On versions 1.3.0 through 1.5.0 of the Windows Authentication Client, users are unable to log in with the Windows Admin Console.
-
Fixed: Users in a locked or disabled state can log in to the Windows Authentication Client if the client is in disconnected mode.