Integration Manual: Biometric MFA

Guide for installing and configuring FaceSign Biometric MFA on Windows, ensuring facial authentication with liveness proof when accessing the system.


Prerequisites

  • Administrator Credentials: The client software installation requires local administrator privileges on the machine.

  • Configuration Information: Before starting, obtain from the Facesign technical team the environment variable value and your Client ID (ClientID). These data are unique to each organization.


Configuration Procedure

The integration is carried out in three main steps: setting the environment variable, installing the MFA client and authentication.


Step 1: Setting the Environment Variable

You need to create an environment variable in the system so that the MFA client can communicate with the Facesign platform.

  1. Access the Control Panel in Windows.

  1. Navigate to System and then click Advanced system settings.

  2. On the Advancedtab, click the Environment Variables....

  1. In the System variablessection, click New... to add a new variable.

  2. Fill in the fields as follows:

  • Variable name: MFAFaceSign

  • Variable value: Enter here the full value (usually in JSON format) provided by the Facesign technical team.

  1. Click OK in all windows to confirm and save the changes.

Environment Variable Parameters

The value of the variable MFAFaceSign is a JSON object that may contain several parameters to customize the behavior of the MFA client. The table below describes the main available parameters.

Parameter
Description

MFALogonWindows

Require biometrics when powering on the machine

MFAUnlockWindows

Require biometrics on unlock

BlockKeyBoardShortCuts

Blocks keyboard shortcut keys

BreakGlass

Disables all functions (default "false")

ClientURL

Client portal URL (facesign app)

MonitoringURL

Monitoring link (internal use)

ClientID

Unique client ID (facesign app)

UpdateURL

Version update URL


Step 2: Installation of the MFA Client

With the environment variable configured, the next step is to install the client software.

  1. Run the Biometric MFA installer file (.msi) provided by Facesign.

  1. On the welcome screen, proceed to the next step.

  2. When prompted, enter your Client ID (ClientID) in the corresponding field. This ID is the same used in the environment variable.

  1. Continue with the installation, advancing through all steps until completion. The process may take a few minutes to start the necessary services.

  1. At the end, click Finish to close the installer.


Step 3: Authentication and Access

After successful installation, biometric authentication will be requested as configured.

  1. On the Windows logon or unlock screen, the Facesign prompt will be displayed.

  2. Perform the 3D biometric verification according to the on-screen instructions.

  3. After successful validation, access to the system will be granted.

Congratulations! You now have a new level of security and innovation!


Support and Contact

With Facesign's Biometric MFA solution, your organization adds a robust layer of security and innovation to accesses. If you have any questions or need technical support, contact our team via email: contato@facesign.inenvelope.

Last updated