
Thisprocessisinitiatedautomaticallyontheclientsystembasedonpolicy,andadministratorcorporate
credentialsareobtainedfromtheHardwarePasswordManagerservertoallowtheregistrationtoproceed
unattended.
Note:One-touchreferstotheonemanualsteprequiredbytheadministratortoregisterthesystemin
HardwarePasswordManager.Whenthesystemisregisteredanddeliveredtousers,enrollmentcan
automaticallybeinitiated(basedonpolicy)foranyusersuccessfullyloggingintoWindowsonthesystem,
eitheralocalordomainlogin.Theone-touchregistrationprocessisignoredifthesystemisalready
registered.
Pre-registration
Thisprocessisthesameasthenormalregistrationprocess,exceptforthefollowingdifferences:
1.Basedonpolicy,theclientportal(whichisautomaticallylaunchedwhenloggingintoWindows)initiates
theone-touchHardwarePasswordManagerregistrationfunctionbasedontheone-touchpolicysetting.
2.Theclientportaldoesnotpromptforconrmationtoproceedwiththeregistrationandenrollment.
3.Afterrestarting,pressEnteratConrmRegistration.
4.Theclientportaldoesnotpromptforcorporate,Windows,orhardwareaccountcredentials.The
corporatecredentialsusedtoauthenticatetheregistrationrequestaretheadministrator-levelcredentials
providedbytheadministratorwhenconguringLDAPintheAdminConsole.TheWindowsand
hardwareaccountcredentialsarenotrequiredsincenouseraccountiscreated;onlythecommon
Administratoraccountisenrolled.
5.Theclientportalproceedswiththesuspendandresumeoperationwithoutnotifyingtheuser.
6.Theclientportalreturnsasuccessorfailurecodetothecallingprocessandrestartsautomatically.
Whentheone-touchregistrationprocesscompletes,thesystemispassword-protectedandasinglelocal
hardwareaccountiscreated.Thehardwareaccountissettothecommonadministratorhardwareaccount
credentials.Thesesystemscanbesafelydistributedbytheadministratortoendusersknowingthatthey
areprotectedwithhardwarepasswords.
Userenrollmentonapre-registeredsystem
Whenthesystemisdeliveredtotheuser,theusershouldperformaHardwarePasswordManagerlogin
(wirednetworkconnectionisrequired)inordertogainaccesstothesystem.Ifnonetworkconnectionis
availableortheHardwarePasswordManagerserverisbehindaVPN,theadministratorhastheoptionto
providethecommonadministratorhardwareaccountcredentialstoallowaccesstothesystem.Thisowis
thesameasthenormalEnrollAdditionalUsersow.
Chapter5.Deployment27
Kommentare zu diesen Handbüchern