Перейти до інформації про товар
1 з 1
Part of Hideez Workforce Identity

Hideez Authenticator

Hideez Authenticator

Hideez Authenticator gives every employee a corporate credential without issuing them anything — passwordless MFA for web accounts and passwordless Windows login for the shared workstations your teams rotate through.

There is no hardware to buy, ship or replace: staff use the phone they already carry. You approve each workstation, hand out and revoke login methods from one console, and every sign-in on a shared account still carries a named person in the audit trail.

Free to download. Enterprise use is included in a Hideez Workforce Identity subscription, and you can start with a free trial.

Requirements

On the employee’s phone

  • iOS 14 or later · Android 8 or later
  • Bluetooth 5 for proximity sign-in, walk-away lock and NFC Tap & Go
  • A PIN is set on first use; biometric unlock is recommended

On the workstation

  • Windows 10 (build 1709+), Windows 11 or Windows Server 2022, 64-bit
  • The Hideez Desktop app for Windows
  • An HTTPS connection to your Hideez tenant
  • NTAG216 NFC tags for Tap & Go — ordinary stickers, no card readers
Детальніше
See it work

Watch a sign-in end to end

An employee unlocks a Windows workstation from the lock screen, then signs in to a web application, without typing a password either time.

One app covers both, and nothing is issued to the employee beyond an invitation.

Watch a sign-in end to end
Why IT buys it

What changes for your team

No passwords on shared workstations

Staff sign in with the phone they already carry. Nothing to rotate, nothing taped to a monitor, nothing to reset at 7 a.m.

No hardware to buy or replace

No tokens, no cards, no readers. Joining and leaving becomes a console entry instead of a hardware handover.

Named access on shared accounts

Several people, one Windows account, and a log that still says who opened the session and when.

Sessions that close themselves

The workstation locks when the phone leaves Bluetooth range. Unattended sessions stop being an audit finding.

Passwordless MFA and passwordless Windows login from one app. Workstation sign-in needs the Hideez Client on Windows 10 (build 1709+), 11 or Server 2022; proximity and Tap & Go also need Bluetooth 5 on both devices.

How it works

Four ways in, one app

How staff unlock Windows with a phone, reach the web applications behind it, and keep working when the network does not.

Scan a QR code
Bluetooth proximity
NFC Tap & Go

The lock screen shows a QR code. The employee scans it in the app and approves the request. This route works on any workstation running the Hideez Client app.

The employee opens the app next to the machine, picks it from the list and taps the Bluetooth icon. Both devices need Bluetooth 5.

An NFC tag on the workstation. Unlock the app with a fingerprint, hold the phone to the tag, and the session opens. Built for shifts where seconds count.

Passwordless SSO
Approved, never typed
Shared accounts

Your SAML and OIDC applications offer “Sign in with Hideez Authenticator”. The employee scans the code on screen and approves on the phone.

Where a password still applies, the confirmation happens on the employee’s own device instead of in a field on the page.

Where a team shares a service account, the app lists the accounts that employee may open and records who used it.

Offline codes
Password-based mode

No connection to the server, no blocked employee: the app produces a one-time code tied to that workstation.

Where a workstation is not joined to Active Directory or Entra ID, the app still signs the employee in. The password stays inside the app on the phone.

The same app also generates TOTP codes for third-party services.

One-time password generator →
Your console
Administration

Your console

Workstations register themselves when the client is installed, and none of them accepts a sign-in until you approve it. From there one console holds the login methods, the revocations and the record of who opened which session.

  • Approve every workstation before its first sign-in
  • Add, replace or revoke login methods in one place
  • Cut off a lost phone in minutes, then re-invite
  • Push the Windows client by Group Policy (.msi)
  • Forward the audit trail to your SIEM over syslog
Hideez Server
Security

Nothing on the server to steal

Passwordless MFA changes what an attacker can steal. The credential lives on the employee’s phone. Passwordless sign-in creates no password at all, and where a workstation still needs one, that password is held inside the app on the device — so your server never becomes the thing worth attacking.

The app itself is closed behind a PIN set on first use, with biometric unlock recommended next to it. Three attempts are allowed per PIN change, and five failures start a lockout with three-minute waits. “Exit — erase all data” clears the credential from a phone being retired or reassigned.

Every sign-in is approved on the employee’s own device, so a fake sign-in page has nothing to capture. Traffic between the app and your tenant runs over HTTPS on port 443, and an administrator can remove a login method and re-invite an employee in minutes.

Where a mandate names phishing-resistant MFA specifically, the same platform issues passkeys and FIDO security keys, and employees can carry them next to the app.

Nothing on the server to steal
Microsoft Authenticator alternative

How it compares

Hideez Authenticator Microsoft Authenticator Duo Mobile
Signs in at the Windows lock screen Yes — QR code, Bluetooth or NFC tag No — Windows sign-in uses Windows Hello Yes — second factor, or Passwordless for OS Logon
Bluetooth proximity sign-in Yes No No
Locks the workstation on walk-away Yes, over Bluetooth No No
Tap-to-login with an NFC tag on the machine Yes, NTAG216 sticker No No
Shared-account sign-in on shared machines Yes, recorded per employee No No
Sign-in when the workstation is offline Yes, offline codes Codes only, no workstation login Yes, offline access codes
Keeps a legacy password for the workstation Yes, stored in the app on the phone Autofill retired in 2025 No
TOTP generator for third-party services Yes, configurable digits and period Yes Yes
SAML / OIDC single sign-on Yes, Hideez acts as the IdP Through Microsoft Entra ID Yes, Duo Single Sign-On

Three authenticator apps, and the differences show up at the workstation. Compared in August 2026 against publicly documented capabilities. Duo adds a second factor to the Windows password login and offers passwordless OS logon; the proximity, NFC and shared-account behaviour above is what Hideez adds on top. Teams moving off Okta Verify or Duo Mobile usually arrive for that half of the list.

Proof

What our customers say

Government bodies, manufacturers and critical-infrastructure operators run Hideez Workforce Identity — with the app, with hardware keys, or with both.

Agency for Restoration of Ukraine
Agency for Restoration of UkraineGovernment — watch the story

Our team has extensive hands-on experience with the Hideez system, which allowed us to integrate it into a wide range of products. Over time, the integration process has become increasingly straightforward, and the system continues to evolve by adding new functionalities.

Computer Forensics Lab Ltd. / IT services

The technical implementation of Hideez was smooth. We especially liked the automatic workstation lock and unlock, fast document handling in Siemens EBR, and the convenient use of the password manager for RDP connections with a large number of logins.

Farmak JSC / Manufacturing

Hideez proved to be an efficient 2FA solution for critical infrastructure, and we see strong potential for further improvement as compatibility and stability continue to evolve. It helps us secure video surveillance and video analytics systems used daily by thousands of employees.

National Police of Ukraine / Government
Works with what you already run
Microsoft Entra ID, Active Directory, AD FS, Google Workspace, Okta, GitHub Enterprise, Exchange OWA and ChromeOS — plus anything that speaks SAML 2.0, OIDC or WS-Federation. See the full list of supported services.
FAQ

FAQs

Is Hideez Authenticator free?

The app is free to download from both stores. Using it across an organisation is part of a Hideez Workforce Identity subscription, and you can start with a free trial.

Does it work without Hideez Workforce Identity?

No. The app authenticates against your organisation’s Hideez tenant, so the tenant is what makes it work. It is a component of the platform rather than a standalone authenticator, and the tenant is where your passwordless MFA policy, workstation approvals and audit records live.

Which phones are supported?

iOS 14 or later and Android 8 or later. Proximity sign-in, walk-away lock and NFC Tap & Go additionally need Bluetooth 5 on the phone and the workstation.

What has to be installed on the workstation?

The Hideez Client app, on Windows 10 (build 1709 or later), Windows 11 or Windows Server 2022, 64-bit. It ships as an .exe, or as an .msi for Group Policy deployment.

Can employees sign in when a workstation has no connection to the server?

Yes. The app produces a one-time offline code for that machine and the employee enters it at the lock screen.

How does the walk-away lock work?

The workstation watches for the phone over Bluetooth and locks the session when the phone leaves range or Bluetooth goes off. The app also carries a Lock workstation button.

Do we need NFC readers?

No. Tap & Go uses NTAG216 stickers on the machines, tags that cost cents. The phone reads the tag to identify the workstation and the sign-in travels over Bluetooth.

Where are passwords stored?

Passwordless sign-in creates none. Where a workstation still needs one, it is held inside the app on the employee’s phone behind a PIN and biometrics, and your server keeps no password database.

What happens when an employee loses the phone?

An administrator removes that login method from the employee’s profile, which stops the lost device from signing in, and sends a fresh enrollment invitation.

Can one phone hold several accounts or tenants?

Yes. One app holds several accounts across the same or different Hideez servers, with an account picker when more than one applies.

Is Hideez Authenticator a Microsoft Authenticator alternative?

For MFA on Microsoft accounts the two overlap. Hideez adds what happens at the workstation: unlocking Windows over QR code, Bluetooth or an NFC tag, locking the machine when the employee walks away, opening shared accounts, and working while the workstation is offline.

Can we deploy it centrally?

The app comes from the public stores and can be pushed by your MDM. The Windows client deploys by Group Policy with the .msi package.

Is this a passkey or a FIDO2 authenticator?

Hideez Authenticator is Hideez’s own enterprise authentication method. Passkeys and FIDO security keys are separate login methods inside the same platform, and employees can use them next to the app.

Is Hideez Authenticator phishing-resistant MFA?

Under the CISA and NIST definition, phishing-resistant MFA means FIDO2/WebAuthn or PIV. Hideez Authenticator uses its own protocol, so the honest answer is that it removes the password an attacker would phish and moves approval onto the employee’s own device. Where a mandate names phishing-resistant MFA specifically, the same platform issues passkeys and FIDO security keys, and employees can carry both.

How does it compare with Windows Hello?

Windows Hello signs a person into the machine in front of them with a fingerprint or a face. Hideez Authenticator covers what Hello does not: one credential across every shared workstation, a session that locks as the employee walks away, shared-account sign-in, and access when the machine is offline. Both can run on the same fleet.

Get started

See it on your own workstations

A short session with our team: we spin up a tenant, install the Windows client on one machine and sign in from a phone. Bring the scenario you care about — shared terminals, sites that lose connectivity, or a Microsoft Authenticator you would like to reach further.

Employees download the app free from the App Store or Google Play.