> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md).

# Behavior Authentication

<figure><img src="/files/38QUmPhekl5156i1E7or" alt="Behavior Authentication User journey"><figcaption></figcaption></figure>

***

### Overview

Behavioral Authentication is particularly useful in environments requiring complex passwords (14–16 characters for PCI DSS compliance). With Behavioral Authentication and PIN enrolled, users can log in without repeatedly typing long passwords.

Both factors are enrolled and used via the **Windows Workstation MFA Agent**.

### Credential Provider

Both factors are enrolled and used via the Windows Workstation MFA Agent.

#### **Admin Setup**

**Enabling Behavior Auth and PIN Enrollment**

Both PIN Enrollment and Behavior Auth Enrollment are disabled by default and must be explicitly enabled before users can enroll or authenticate with this method.

1. In AdminX, navigate to **Applications > Windows MFA > Settings > Enrollment Preferences**.
2. Toggle PIN Enrollment to ON.
3. Toggle Behavior Auth Enrollment to ON.
4. Save the settings.

Users will not see enrollment prompts or Behavior Auth login options until both toggles are enabled.

**Configuring the Authentication Journey**

1. In AdminX, navigate to **Applications > Windows MFA > Adaptive Auth Journeys**.
2. Create a new journey or edit an existing one.
3. Under Authentication Method, select **Behavior Auth & PIN**.
4. Assign the journey to the target user group or machine policy.
5. Save and publish the journey.

***

### AdminX

Behavior Authentication is now also supported for AdminX login. Administrators can configure it as an adaptive authentication method and enroll their typing pattern directly from their AdminX profile.

**Admin Setup**

Configuring Behavior Auth in Adaptive Authentication

1. Log in to AdminX as a community admin.
2. Navigate to **Authentication > Adaptive Authentication**.
3. Click Add new adaptive auth journey.
4. Enter a Journey Name and ensure the Enabled toggle is ON.
5. Set the Conditions as required (for example, restrict by application or username).
6. Under Decision, set Action to MFA Required.
7. From the authentication method list, select Behavior Auth & PIN, *Prompts the user to log in with their typing pattern and PIN.*
8. Click **Save**.

**Enrolling Behavior Auth and PIN**

Administrators enroll their typing pattern directly from their AdminX profile.

1. Navigate to **My Profile > Login Options**.
2. Click the **Setup** dropdown and select **Behavior auth (Beta)**.
3. On the Setup Behavior Authentication screen, click **Continue to enroll**.
4. On the **Capture Typing Pattern** screen, type the displayed phrase exactly as shown in the Your input field — type naturally, as the system captures your rhythm.
5. Complete all 5 attempts and click **Finish enrollment**.
6. The enrolled Typing Pattern appears under **Login Options**.

{% hint style="info" %}
PIN enrollment is a separate step. If PIN is not yet enrolled, select Pin from the Setup dropdown and complete PIN enrollment before using Behavior Auth & PIN to log in.
{% endhint %}

**Logging in to AdminX**

1. On the AdminX Sign in screen, select the **Username** tab.
2. Enter your Corporate Username and click Next.
3. On the **Capture Typing Pattern** screen, type the displayed phrase exactly as shown in the Your input field and click **Next**.
4. On the **Enter your PIN** screen, enter your 4-digit PIN and click Submit.
5. You are signed in to the AdminX interface.

{% hint style="info" %}
The typing pattern screen appears only if Behavior Auth & PIN is configured as the authentication method in the adaptive auth journey assigned to your account. If you are not prompted for a typing pattern, verify the journey configuration with your administrator.
{% endhint %}

**Configuring Fallback Authentication (v2.2.0.0+)**

Fallback authentication allows a helpdesk-generated passcode to be used when a user cannot complete Behavior Auth & PIN after repeated failures.

{% stepper %}
{% step %}
In AdminX, navigate to **Applications > Windows MFA > Settings > Authentication Preferences**.
{% endstep %}

{% step %}
Enable the **Fallback Journeys** slider.
{% endstep %}

{% step %}
Set the **Trigger fallback after number of attempts** value to the desired threshold.
{% endstep %}

{% step %}
Create or select a separate Adaptive Auth Journey with the **Admin Passcode** authentication method.
{% endstep %}

{% step %}
Assign this journey as the **Fallback Auth Journey**.
{% endstep %}

{% step %}
Save the settings.
{% endstep %}
{% endstepper %}

To generate a helpdesk passcode for a specific user:

{% stepper %}
{% step %}
In AdminX, navigate to **Users > All Users**.
{% endstep %}

{% step %}
Locate the user and click the **three-dot menu** next to their name.
{% endstep %}

{% step %}
Select **Generate Passcode**.
{% endstep %}

{% step %}
Set the passcode expiry (range: 1 minute to 24 hours; default: 10 minutes).
{% endstep %}

{% step %}
Provide the generated passcode to the user via a secure out-of-band channel.
{% endstep %}
{% endstepper %}

***

### Enrollment

Enrollment is triggered automatically on the user's first login after Behavior Auth is enabled. Users cannot be pre-enrolled by an administrator.

{% stepper %}
{% step %}
The user completes their normal authentication flow (e.g., password + OTP) as usual.
{% endstep %}

{% step %}
After successful primary authentication, the enrollment prompt appears.
{% endstep %}

{% step %}
A phrase is displayed on screen. The user types the phrase the configured number of times. Each entry captures the user's natural typing rhythm and cadence. Enrollment is complete when the required number of samples have been accepted.
{% endstep %}

{% step %}
The user is prompted to create a PIN. PIN length and complexity requirements are determined by the organisation's policy configured in AdminX. The user enters the PIN twice to confirm.
{% endstep %}

{% step %}
Enrollment is saved to the user's profile.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Users can click **Skip** to bypass enrollment and log in normally. They will be prompted to enroll again on the next login attempt. Enrollment cannot be permanently skipped — the prompt recurs until enrollment is completed.
{% endhint %}

### User Guide

**Standard Login with Behavior Auth & PIN**

{% stepper %}
{% step %}
At the Windows login screen, click the **1Kosmos** tile.
{% endstep %}

{% step %}
If using the **Other User** tile, enter your username first.
{% endstep %}

{% step %}
Select **Behavior Auth** from the available authentication options.
{% endstep %}

{% step %}
A phrase is displayed on screen. Type the phrase naturally, do not alter your typing speed or style.
{% endstep %}

{% step %}
After the phrase is accepted, enter your PIN.
{% endstep %}

{% step %}
The Windows session unlocks and you are logged in.
{% endstep %}
{% endstepper %}

**Offline Login with Cached PIN**

When the workstation has no network connectivity, the Credential Provider detects the offline state and presents available offline options.

{% stepper %}
{% step %}
At the Windows login screen, click the **1Kosmos** tile.
{% endstep %}

{% step %}
The Credential Provider detects no connectivity and displays offline authentication options.
{% endstep %}

{% step %}
Select **PIN**.
{% endstep %}

{% step %}
Enter your PIN.
{% endstep %}

{% step %}
The Windows session unlocks and you are logged in.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Offline PIN authentication is limited to **3 attempts**. After 3 failed attempts, the cached PIN is cleared and offline PIN login is no longer available until the device reconnects and the user re-authenticates online. Contact your helpdesk if the cached PIN has been cleared.
{% endhint %}

**Fallback Login (Helpdesk Passcode)**

{% stepper %}
{% step %}
After exceeding the configured number of failed Behavior Auth & PIN attempts, the **Trouble Logging In?** screen appears.
{% endstep %}

{% step %}
Click **Helpdesk Code**.
{% endstep %}

{% step %}
Contact your helpdesk and request a one-time passcode.
{% endstep %}

{% step %}
Enter the passcode provided by the helpdesk.
{% endstep %}

{% step %}
The Windows session unlocks and you are logged in.
{% endstep %}

{% step %}
Optionally, you will be prompted to reset your enrolled typing pattern and/or PIN after logging in via fallback.
{% endstep %}
{% endstepper %}

**Managing Enrolled Pattern and PIN**

Users can view, modify, or delete their enrolled typing pattern and PIN via the AdminX self-service portal.

{% stepper %}
{% step %}
Log in to AdminX.
{% endstep %}

{% step %}
Navigate to **My Profile > Login Options**.
{% endstep %}

{% step %}
Select the **Behavior Auth** or **PIN** entry.
{% endstep %}

{% step %}
Choose to **Modify** or **Delete** the enrolled factor as required.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Deleting an enrolled factor will require re-enrollment at the next login attempt.
{% endhint %}

### Best Practices

**Typing Biometrics, Do's and Don'ts**

| Do                                                               | Don't                                                                            |
| ---------------------------------------------------------------- | -------------------------------------------------------------------------------- |
| Type naturally, at your normal pace                              | Don't intentionally slow down or speed up while typing                           |
| Use the same device and keyboard you enrolled on                 | Don't frequently switch keyboards between enrollment and authentication          |
| Type in lowercase as prompted                                    | Don't type in uppercase or mix case unless instructed                            |
| Complete enrollment carefully, multiple samples improve accuracy | Don't rush through the enrollment phrase entries                                 |
| Perform enrollment in a normal working environment               | Don't let another person type on your behalf during enrollment or authentication |

### Troubleshooting

| Issue                                              | Likely Cause                                                                          | Resolution                                                                                                                                                                        |
| -------------------------------------------------- | ------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Typing pattern not recognised                      | User's typing style has changed; different keyboard used; typing too fast or too slow | Type naturally and at a consistent pace; ensure you are using the same keyboard as during enrollment; if repeated failures occur, proceed through the fallback flow and re-enroll |
| PIN forgotten                                      | User cannot recall their PIN                                                          | Use the fallback authentication flow (Helpdesk Code) to log in, then reset the PIN via **My Profile > Login Options** in AdminX                                                   |
| Account locked after failed Behavior Auth attempts | Maximum failed attempts exceeded before fallback threshold triggered                  | Contact the helpdesk to unlock the account and obtain a fallback passcode                                                                                                         |
| Offline PIN cleared after 3 failed attempts        | Three consecutive incorrect PIN entries in offline mode                               | Reconnect the device to the network; log in online to re-establish the cached PIN                                                                                                 |
| Enrollment prompt not appearing                    | Behavior Auth Enrollment or PIN Enrollment toggle is OFF in AdminX                    | Verify both toggles are enabled in **Applications > Windows MFA > Settings > Enrollment Preferences**                                                                             |
| Fallback option not available                      | Fallback Journeys slider is OFF; fallback journey not configured                      | Enable the Fallback Journeys slider and assign a fallback journey with the Admin Passcode method in Authentication Preferences                                                    |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
