Administrator Guide

Table Of Contents
Imprivata v4.9 or later appliance version is needed that supports the WebAPI v5 and later versions.
Fingerprint identification license is required.
Fingerprint reader device is required. ET710 (PID 147e VID 2016) and ET700 (PID 147e VID 3001) are the supported devices.
Supported user scenarios
Signing in or unlocking the ThinOS devices using the Fingerprint authentication.
Configure the OneSign server on ThinOS, and then connect the Fingerprint reader device.
The ThinOS Fingerprint window is displayed automatically after the OneSign server is initialized.
Fingerprint authentication works on the ThinOS unlock window.
Unlocking the Virtual Desktop using the Fingerprint authentication.
Enable the Imprivata Virtual Channel option from the ThinOS Global Connection settings.
When you lock the virtual desktop in the session, the Fingerprint window is displayed automatically.
Managing Fingerprints on a virtual desktop.
Legend Fingerprint Management is supported.
Fingerprint management with Imprivata Confirm ID enabled is not supported.
Grace period to skip second authentication factor
Grace period enables you to specify a time limit on OneSign server for logging in without the second authentication factor after
the first login session.
NOTE: After you specify the grace period, you must first use the proximity badge, and then enter password or OneSign PIN
for the initial login.
If you use the proximity card after the time limit that you specified for grace period, the second authentication factor window is
displayed with the message Grace period expired.
If you enter a wrong password or PIN, the second authentication factor window is displayed with the warning message OneSign
could not authenticate you. Try again.
Imprivata OneSign ProveID Embedded
ThinOS supports the Imprivata OneSign ProveID Embedded (PIE) feature that enables secure authentication to virtual desktops
and applications. Using this feature, you can seamlessly access the clinical applications. The PIE solution simplifies access to
roaming desktops with Citrix Virtual Apps and Desktops, VMware Horizon Desktops and Applications, and Remote Desktop
Services. You can also deploy a Citrix Virtual App hosted desktop with Fast User Switching (FUS) to eliminate the need for
generic user log-ins. For more information about the Imprivata OneSign ProveID Embedded, see the documentation available at
www.imprivata.com.
Table 43. Supported environment
Component Supported environment
Endpoints (Thin Clients)
Wyse 5470 All-in-One Thin Client
Wyse 5470 Thin Client
Wyse 5070 Thin Client
Wyse 3040 Thin Client
VDI environment
Citrix Desktop
Citrix XenApp
Microsoft Remote Desktop Services session based and virtual desktop
Microsoft Remote Desktop Services Remote PC
VMware Horizon - Desktops
OneSign server (tested) 7.1.005.42
PIE Agent on the thin client 7.1.005.0039
Authentication methods
Network password
Proximity card
Security questions
Configuring third-party authentication settings 141