Configure offline biometrics for Windows
Configure offline biometrics so your users can sign in to their Windows machines using Windows Hello factors (fingerprint or face) and Okta Device Access.
Before you begin
- Ensure that you have administrative access to the Mobile Device Management (MDM) solution used to manage your Windows devices.
- Verify that user devices are equipped with Windows Hello-compatible hardware (fingerprint reader or IR camera).
- Instruct users that they must first enroll in Windows Hello on their local machine before they can use this feature.
After you apply the policy to the device, then the next time a user signs in with their password, Okta Verify prompts them to register their enrolled Windows Hello biometrics for offline use. For future sign-in flows, the Windows credential provider prompts the user for their face or fingerprint instead of a password.