Watch a sign-in end to end
An employee unlocks a Windows workstation from the lock screen, then signs in to a web application, without typing a password either time.
One app covers both, and nothing is issued to the employee beyond an invitation.
What changes for your team
No passwords on shared workstations
Staff sign in with the phone they already carry. Nothing to rotate, nothing taped to a monitor, nothing to reset at 7 a.m.
No hardware to buy or replace
No tokens, no cards, no readers. Joining and leaving becomes a console entry instead of a hardware handover.
Named access on shared accounts
Several people, one Windows account, and a log that still says who opened the session and when.
Sessions that close themselves
The workstation locks when the phone leaves Bluetooth range. Unattended sessions stop being an audit finding.
Passwordless MFA and passwordless Windows login from one app. Workstation sign-in needs the Hideez Client on Windows 10 (build 1709+), 11 or Server 2022; proximity and Tap & Go also need Bluetooth 5 on both devices.
Four ways in, one app
How staff unlock Windows with a phone, reach the web applications behind it, and keep working when the network does not.



The lock screen shows a QR code. The employee scans it in the app and approves the request. This route works on any workstation running the Hideez Client app.
The employee opens the app next to the machine, picks it from the list and taps the Bluetooth icon. Both devices need Bluetooth 5.
An NFC tag on the workstation. Unlock the app with a fingerprint, hold the phone to the tag, and the session opens. Built for shifts where seconds count.



Your SAML and OIDC applications offer “Sign in with Hideez Authenticator”. The employee scans the code on screen and approves on the phone.
Where a password still applies, the confirmation happens on the employee’s own device instead of in a field on the page.
Where a team shares a service account, the app lists the accounts that employee may open and records who used it.


No connection to the server, no blocked employee: the app produces a one-time code tied to that workstation.
Where a workstation is not joined to Active Directory or Entra ID, the app still signs the employee in. The password stays inside the app on the phone.
The same app also generates TOTP codes for third-party services.
One-time password generator →
Your console
Workstations register themselves when the client is installed, and none of them accepts a sign-in until you approve it. From there one console holds the login methods, the revocations and the record of who opened which session.
- Approve every workstation before its first sign-in
- Add, replace or revoke login methods in one place
- Cut off a lost phone in minutes, then re-invite
- Push the Windows client by Group Policy (.msi)
- Forward the audit trail to your SIEM over syslog
Nothing on the server to steal
Passwordless MFA changes what an attacker can steal. The credential lives on the employee’s phone. Passwordless sign-in creates no password at all, and where a workstation still needs one, that password is held inside the app on the device — so your server never becomes the thing worth attacking.
The app itself is closed behind a PIN set on first use, with biometric unlock recommended next to it. Three attempts are allowed per PIN change, and five failures start a lockout with three-minute waits. “Exit — erase all data” clears the credential from a phone being retired or reassigned.
Every sign-in is approved on the employee’s own device, so a fake sign-in page has nothing to capture. Traffic between the app and your tenant runs over HTTPS on port 443, and an administrator can remove a login method and re-invite an employee in minutes.
Where a mandate names phishing-resistant MFA specifically, the same platform issues passkeys and FIDO security keys, and employees can carry them next to the app.

How it compares
| Hideez Authenticator | Microsoft Authenticator | Duo Mobile | |
|---|---|---|---|
| Signs in at the Windows lock screen | Yes — QR code, Bluetooth or NFC tag | No — Windows sign-in uses Windows Hello | Yes — second factor, or Passwordless for OS Logon |
| Bluetooth proximity sign-in | Yes | No | No |
| Locks the workstation on walk-away | Yes, over Bluetooth | No | No |
| Tap-to-login with an NFC tag on the machine | Yes, NTAG216 sticker | No | No |
| Shared-account sign-in on shared machines | Yes, recorded per employee | No | No |
| Sign-in when the workstation is offline | Yes, offline codes | Codes only, no workstation login | Yes, offline access codes |
| Keeps a legacy password for the workstation | Yes, stored in the app on the phone | Autofill retired in 2025 | No |
| TOTP generator for third-party services | Yes, configurable digits and period | Yes | Yes |
| SAML / OIDC single sign-on | Yes, Hideez acts as the IdP | Through Microsoft Entra ID | Yes, Duo Single Sign-On |
Three authenticator apps, and the differences show up at the workstation. Compared in August 2026 against publicly documented capabilities. Duo adds a second factor to the Windows password login and offers passwordless OS logon; the proximity, NFC and shared-account behaviour above is what Hideez adds on top. Teams moving off Okta Verify or Duo Mobile usually arrive for that half of the list.
Proof
What our customers say
Government bodies, manufacturers and critical-infrastructure operators run Hideez Workforce Identity — with the app, with hardware keys, or with both.




































FAQs
Is Hideez Authenticator free?
The app is free to download from both stores. Using it across an organisation is part of a Hideez Workforce Identity subscription, and you can start with a free trial.
Does it work without Hideez Workforce Identity?
No. The app authenticates against your organisation’s Hideez tenant, so the tenant is what makes it work. It is a component of the platform rather than a standalone authenticator, and the tenant is where your passwordless MFA policy, workstation approvals and audit records live.
Which phones are supported?
iOS 14 or later and Android 8 or later. Proximity sign-in, walk-away lock and NFC Tap & Go additionally need Bluetooth 5 on the phone and the workstation.
What has to be installed on the workstation?
The Hideez Client app, on Windows 10 (build 1709 or later), Windows 11 or Windows Server 2022, 64-bit. It ships as an .exe, or as an .msi for Group Policy deployment.
Can employees sign in when a workstation has no connection to the server?
Yes. The app produces a one-time offline code for that machine and the employee enters it at the lock screen.
How does the walk-away lock work?
The workstation watches for the phone over Bluetooth and locks the session when the phone leaves range or Bluetooth goes off. The app also carries a Lock workstation button.
Do we need NFC readers?
No. Tap & Go uses NTAG216 stickers on the machines, tags that cost cents. The phone reads the tag to identify the workstation and the sign-in travels over Bluetooth.
Where are passwords stored?
Passwordless sign-in creates none. Where a workstation still needs one, it is held inside the app on the employee’s phone behind a PIN and biometrics, and your server keeps no password database.
What happens when an employee loses the phone?
An administrator removes that login method from the employee’s profile, which stops the lost device from signing in, and sends a fresh enrollment invitation.
Can one phone hold several accounts or tenants?
Yes. One app holds several accounts across the same or different Hideez servers, with an account picker when more than one applies.
Is Hideez Authenticator a Microsoft Authenticator alternative?
For MFA on Microsoft accounts the two overlap. Hideez adds what happens at the workstation: unlocking Windows over QR code, Bluetooth or an NFC tag, locking the machine when the employee walks away, opening shared accounts, and working while the workstation is offline.
Can we deploy it centrally?
The app comes from the public stores and can be pushed by your MDM. The Windows client deploys by Group Policy with the .msi package.
Is this a passkey or a FIDO2 authenticator?
Hideez Authenticator is Hideez’s own enterprise authentication method. Passkeys and FIDO security keys are separate login methods inside the same platform, and employees can use them next to the app.
Is Hideez Authenticator phishing-resistant MFA?
Under the CISA and NIST definition, phishing-resistant MFA means FIDO2/WebAuthn or PIV. Hideez Authenticator uses its own protocol, so the honest answer is that it removes the password an attacker would phish and moves approval onto the employee’s own device. Where a mandate names phishing-resistant MFA specifically, the same platform issues passkeys and FIDO security keys, and employees can carry both.
How does it compare with Windows Hello?
Windows Hello signs a person into the machine in front of them with a fingerprint or a face. Hideez Authenticator covers what Hello does not: one credential across every shared workstation, a session that locks as the employee walks away, shared-account sign-in, and access when the machine is offline. Both can run on the same fleet.
See it on your own workstations
A short session with our team: we spin up a tenant, install the Windows client on one machine and sign in from a phone. Bring the scenario you care about — shared terminals, sites that lose connectivity, or a Microsoft Authenticator you would like to reach further.
Employees download the app free from the App Store or Google Play.




