laptop-img

TecTANGO: Smart Card Authentication for Desktops

For Okta users to securely access corporate resources without passwords.

Just Tap, and Go!

What is TecTANGO?

TecTANGO is a Credential Provider (CP) for Windows 10 which enables Okta customers to login to Windows using Smart Cards like HID Crescendo C2300, Yubikey FIPS, and other PIV compliant Smart Cards.

In order to login, the user needs to be in physical possession of the smart card (something the user has – 1F) and should know the PIN (something the user knows – 2F) that unlocks the smart card. The security can be further enhanced by adding Okta Verify as additional factor.

TecTANGO Supported Cards

Supported Scenarios

Online Mode

In the online scenario, the user’s Desktop/laptop is connected to the internet and can reach Okta cloud.

The user needs to be in physical possession of the smart card (something the user has – 1F) and should know the PIN (something the user knows – 2F) that unlocks the smart card. The security can be further enhanced by adding Okta Verify as additional factor.

Offline Scenario

In the offline scenario, the user’s Desktop/laptop is not connected to the internet and cannot reach Okta cloud.

In this scenario, TecTANGO will perform the primary and secondary authentication. For secondary authentication, there are 2 options:

  • TOTP: Okta Verify app is leveraged. The OTP generated by the Okta Verify App will have to be entered during the 2 Factor prompt. The user will have to scan a QR code using the Okta Verify app on first login to complete the enrollment process for offline 2 Factor authentication.
  • U2F (Universal 2nd Factor): Security keys like Yubikey is used in U2F mode

TecTANGO Requirements

  • Okta tenant with Factor Sequencing Feature – Adaptive MFA
  • Domain user should exist in Okta and is enrolled in Okta Verify
  • TecTANGO Windows Credential Provider – can be installed through SCCM
  • AD Domain Services (AD DS) & PKI through Active Directory Certificate Services (AD CS)
  • Domain Joined Windows 10 Machines with Smart Card Authentication enabled
  • Smart Card like HID Crescendo C2300 Card, Yubikey FIPS, etc.
  • Contact/Contactless Smart Card Reader like HID Omnikey 5422 Card Reader, etc.
  • Smart Card drivers compatible with the device
  • Smart Card users must know their Smart Card PIN
  • User Certificate enrollment using Smart Card
Does TecTANGO support Windows 10?

TecTANGO supports Windows 10 1909 or lower.

What is the Hardware/Software requirements for deploying TecTANGO?

Desktops with Windows 10 for deploying TecTANGO Credential Provider (CP). The CP can be deployed through GPO.

What are the prerequisites for deploying & testing TecTANGO?
    • Okta tenant with Factor Sequencing Feature – Adaptive MFA
    • Domain user should exist in Okta and is enrolled in Okta Verify
    • TecTANGO Windows Credential Provider – can be installed through SCCM
    • AD Domain Services (AD DS) & PKI through Active Directory Certificate Services (AD CS)
    • Domain Joined Windows 10 Machines with Smart Card Authentication enabled
    • Smart Card like HID Crescendo C2300 Card, Yubikey FIPS, etc.
    • Contact/Contactless Smart Card Reader like HID Omnikey 5422 Card Reader, etc.
    • Smart Card drivers compatible with the device
    • Smart Card users must know their Smart Card PIN
    • User Certificate enrollment using Smart Card
Does offline enrollment with the Okta Verify app conflict with my account Enrolled with Okta?

No, during offline enrollment, the new account gets registered with the Okta Verify app.

How do I install TecTANGO?

TecTANGO supports silent installation or installation via GPO or any standard software distribution tools like Microsoft System Center Configuration Manager.

What do Okta users need to use TecTANGO?

TecTANGO is developed on Okta's MFA framework and leverages on the policies and factors (Okta Verify) configured in Okta. The requirements from end user perspective are, access to a Desktop with TecTANGO Windows Credential Provider installed and a smartcard with a loaded certificate.

Does TecTANGO support UI branding?

TecTANGO provides an option to add company logo for corporate branding.