Enrolling Users and their Credentials

DigitalPersona provides the following credential enrollment methods:

  • Attended enrollment - Using DigitalPersona Attended Enrollment

    Attended enrollment is the default means of enrolling users through the DigitalPersona Enrollment application.

  • Web-based enrollment - Using DigitalPersona Web-Based Enrollment

    HID DigitalPersona Enrollment is a web-based application that provides both attended (supervised) and unattended (self) enrollment and management of DigitalPersona credentials.

    It is compatible with most web browsers on popular desktop and mobile platforms.

  • Self-Enrollment using the DigitalPersona Credential Manager - Managing Your Credentials

    Self-enrollment allows DigitalPersona users to enroll and manage their own credentials.

    Note: By default, self-enrollment is disabled because the Attended Enrollment component is most often used to enroll user credentials. Also, use of the Credential Manager requires a connection to the DigitalPersona Server. If no Server is available, a warning will display, and no tiles will be shown on the Credential Manager page.

    If you want to allow end users to enroll and manage their own DigitalPersona credentials, see Policies and Settings. However, the best practice is to not enable self-enrollment if Attended Enrollment will be used in the environment.

    The credentials that will be available to a user for verifying their identity may be configured through GPO policies and settings (for managed workstations) by a DigitalPersona Administrator or (if not managed) by the local administrator of the computer.

    Unless otherwise specified through a GPO, any hardware or software credential available will be listed in Credential Manager, and may be managed by the user when self-enrollment has been enabled by the DigitalPersona administrator.

Role of the DigitalPersona Identity Server

The DigitalPersona Identity Server (provided through STS or the Secure Token Service) is the authentication gateway for the DigitalPersona Enrollment application.

To use DigitalPersona Enrollment, administrators, Security Officers and other users first need to log in to the Identity Server - see User Onboarding through the Identity Provider.

Login Scenarios (Attended and Self-Enrollment)

There is a slight variation in the UI behavior and workflow for administrators and non-administrative users, and for initial and subsequent logins.

The following is a summary of the steps for different scenarios.

More detailed instructions are provided in the following sections.

Topics in this section: