Unlocking Devices
If a FIDO device PIN becomes locked, it is typically irrecoverable and normally requires a device reset, which results in the loss of all stored credentials.
However, using the Device Unlock service in Customer Central, you can unlock the PIN, allowing users to set a new PIN and continue using their existing credentials.
You have a valid license for the Device Unlock service
To purchase new licenses or renew existing ones, contact your HID Account Manager.
The user has a locked FIDO device with a blocked PIN
The help desk operator has access to Customer Central with the Device Unlock service enabled
Distribute the Device Unlock Application
-
Select Device Management
in the left menu.
-
Select Downloads under FIDO Management.
-
Click DOWNLOAD for the Device Unlock application.
-
Make the application available to your users for download via your organization’s software distribution channel (for example, the approved unified endpoint management (UEM) tools).
It is also recommended to provide installation and usage instructions.
User - Unlock Your Device
As a user, you can unlock your device in coordination with your help desk operator (or IT administrator).
-
Download the Device Unlock application as instructed by your help desk.
-
Double-click the .msix file to launch the setup.
-
Click Install.
-
Click Launch.
-
Insert the locked FIDO device into the machine's USB port or place/insert the locked smart card into the reader.
The application detects the device and displays the information.
-
Provide the Device ID displayed by the Device Unlock application to your help desk operator.
-
Provide the Device Challenge code displayed by the Device Unlock application to your help desk operator.
-
Enter the Response Code provided by your help desk operator.
-
Enter and confirm a New PIN.
The PIN must meet the following conditions:
-
Minimum length - 6 alphanumeric characters
-
Maximum length - 63 alphanumeric characters
-
-
Click UNLOCK.
Help Desk - Unlock a Device for a User
-
Select Device Management
in the left menu.
-
Select Devices under FIDO Management.
-
Search for the user using the Provisioned To filter.
Alternatively, ask the user for the Device ID displayed by the Device Unlock application to locate the locked device.
The list is dynamically updated with the corresponding device(s).
-
Click UNLOCK.
-
Ask the user for the Device Challenge code displayed by the Device Unlock application:
Note: The challenge must be 32 characters (alphanumeric). -
Click GENERATE RESPONSE CODE.
-
Give the generated Response Code to the user and instruct them to enter it in the corresponding field.
-
Instruct the user to set a New PIN and click UNLOCK.
-
Click DONE when the device is successfully unlocked.