> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md).

# Fallback Authentication

***

### Overview

When users sign in to Windows, authentication is typically performed using their primary authentication method. However, in certain situations, users may be unable to authenticate successfully. For example:

* Behavioral Authentication may fail due to changes in the user's typing patterns.
* A user may forget their PIN.

To prevent unnecessary workstation lockouts, 1Kosmos provides a configurable fallback authentication mechanism for Windows login. This feature allows administrators to define a secure secondary authentication method that users can use when the primary method fails.

In such cases, users can contact the Helpdesk to obtain a temporary one-time passcode (OTP). The OTP allows the user to securely sign in to Windows and reset one enrolled authentication factor, such as Behavioral Authentication or PIN.

{% hint style="info" %}
The fallback authentication mechanism is currently supported only for users enrolled in Behavioral Authentication and PIN authentication methods. Users must have previously enrolled in one or both of these methods to use fallback authentication.&#x20;
{% endhint %}

### How It Works

Community Administrators can configure a fallback auth journey within the AdminX interface as part of the Windows MFA Fallback Authentication Journeys.

As part of this configuration:

* Passcodes are enabled as an authentication factor.
* Community Administrators, or users with the **user.helpdesk-passcode.generate** permission , can generate a passcode from a user's profile.
* The user can authenticate their Windows workstation using the passcode and then reset the failed authentication factor in the 1Kosmos Credential Provider before logging in.

The fallback authentication process consists of three key stages that enable secure account recovery for users locked out due to behavioral authentication failure:

* [Setting up Fallback Authentication](#step-1-setting-up-fallback-authentication)
* [User login experience when fallback is triggered](#step-2-user-login-experience-when-fallback-is-triggered)
* [Generating passcodes](#step-3-generating-passcodes)

### Step 1: Setting Up Fallback Authentication

This step involves enabling the Fallback Authentication Journeys tab in the AdminX interface and configuring the fallback authentication workflow.

#### Enabling the Display of Fallback Auth Journeys Tab on AdminX Interface

To display the Fallback Auth Journeys tab:

{% stepper %}
{% step %}

#### Log in

Log in to your tenant as a community administrator.&#x20;
{% endstep %}

{% step %}

#### Open Windows MFA settings

Navigate to **Applications > Windows MFA > Settings**.&#x20;
{% endstep %}

{% step %}

#### Go to Authentication Preferences

Go to the **Authentication Preferences** section.&#x20;
{% endstep %}

{% step %}

#### Turn on Fallback Journeys

Turn the **Fallback Journeys** slider ON. By default, the slider is turned off.&#x20;
{% endstep %}

{% step %}

#### Set the trigger threshold

In the **Trigger fallback after number of attempts** field that appears after turning the slider ON, specify the number of attempts after which the fallback journey is triggered once a user has failed the auth attempts that many times.&#x20;
{% endstep %}

{% step %}

#### Save

Click **Save**.
{% endstep %}
{% endstepper %}

### Configuring Fallback Auth Journeys

Community administrators can use the Fallback Auth journeys tab to configure a fallback journey and define the authentication method to be used for that journey.

To configure a fallback auth journey:

1. Log in to your tenant as a community administrator.

2. Navigate to **Applications > Windows MFA**. The Windows MFA page is displayed.

3. Click the **Fallback Auth journeys** tab.

4. To add a new journey, click **Add new fallback journey**.

5. In the page that is displayed, provide the following details:

   a. Provide a descriptive name for the journey.

   b. Define Conditions from the following options.

   | Condition    | Operator            | Description                                                                                                                                                                                        |
   | ------------ | ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
   | Groups       | is one of           | Select this option to apply the journey only to specific AD groups. You can choose from a list of predefined groups, and the journey will apply only if the AD group exactly matches one of those. |
   | Groups       | is not one of       | The journey applies to all other groups except for the ones mentioned.                                                                                                                             |
   | Groups       | contains            | Select this option if you want the journey to apply to any AD group whose name includes a specific keyword or phrase.                                                                              |
   | Groups       | does not contain    | Select this option to apply the journey for all other groups that do not include the specified keyword or phrases.                                                                                 |
   | Username     | is one of           | Specify the list of users for whom this journey is applicable.                                                                                                                                     |
   | Username     | is not one of       | The journey applies to all other users except for the ones mentioned.                                                                                                                              |
   | Username     | contains            | Select this option if you want the journey to apply to any user whose name includes a specific keyword or phrase.                                                                                  |
   | Username     | does not contain    | Select this option to apply the journey for all other usernames that do not include the specified keywords or phrases.                                                                             |
   | Username     | starts with         | Select this option to apply the journey for usernames that begin with the specified characters or words.                                                                                           |
   | Username     | does not start with | Select this option to apply the journey for all other usernames that do not begin with the specified characters or words.                                                                          |
   | Username     | ends with           | Select this option to apply the journey for users whose names end with specified characters or words.                                                                                              |
   | Username     | does not end with   | Select this option to apply the journey for all other usernames that do not end with the specified characters or words.                                                                            |
   | Machine Name | is one of           | Specify the machine name to which this journey has to be applied.                                                                                                                                  |
   | Machine Name | is not one of       | The journey applies to all other machines except for the ones mentioned.                                                                                                                           |

   c. Define the outcome for each condition. You can select the "MFA Required" action for a journey. The following table provides the supported authentication methods for the above actions:

   | Authentication Method | Description                                        |
   | --------------------- | -------------------------------------------------- |
   | Admin Passcode        | Prompts users to enter a passcode to authenticate. |

   d. Click **Save**.

   You can disable a fallback authentication journey by editing the journey and disabling the slider beside the journey name.

### Editing Fallback Auth Journey

Community administrators can modify or update the fallback auth journey in the AdminX interface.

To modify the auth journey:

{% stepper %}
{% step %}

#### Log in

Log in to your tenant as a community administrator.
{% endstep %}

{% step %}

#### Open Windows MFA

Navigate to **Applications > Windows MFA**.&#x20;
{% endstep %}

{% step %}

#### Find the journey

In the **Fallback Auth Journeys** page that is displayed, navigate to the journey that you want to modify.&#x20;
{% endstep %}

{% step %}

#### Edit the journey

Under the **Actions** column, click the pencil icon in line with the row that you want to edit.
{% endstep %}

{% step %}

#### Save changes

Modify the required details and click **Save**.
{% endstep %}

{% step %}

#### Deleting Fallback Auth Journey

Community administrators can use the AdminX interface to delete a fallback auth journey.

To delete a fallback auth journey:
{% endstep %}

{% step %}

#### Log in

Log in to your tenant as a community administrator.&#x20;
{% endstep %}

{% step %}

#### Open Windows MFA

Navigate to **Applications > Windows MFA**.
{% endstep %}

{% step %}

#### Find the journey

In the **Fallback Auth Journeys** page that is displayed, navigate to the journey that you want to delete.&#x20;
{% endstep %}

{% step %}

#### Delete the journey

Click the Delete icon beside the journey that you want to delete. The auth journey is deleted.&#x20;
{% endstep %}
{% endstepper %}

### Step 2: User Login Experience when Fallback is Triggered

This section describes the user's login flow when fallback authentication is triggered due to behavioral authentication failure. The following steps outline the screens displayed to the user and the actions required to proceed.

When behavioral authentication fails during Windows login, fallback authentication is triggered. Follow the steps below to complete the sign-in process.

#### Enter your username

{% stepper %}
{% step %}

#### **On the Sign In – Enter your username screen, enter your username and press Enter.**&#x20;

{% endstep %}

{% step %}

#### Choose Behavior Auth

On the **Sign In – Choose an authentication method** screen, click **Behavior Auth**.
{% endstep %}

{% step %}

#### Enter the phrase

Enter the phrase displayed on the screen and press Enter.
{% endstep %}

{% step %}

#### Enter the PIN

Enter the PIN and press Enter.
{% endstep %}

{% step %}

#### Fallback is triggered

Based on the number of attempts configured in the AdminX interface (**Trigger fallback after number of attempts** field), if a user enters an incorrect PIN and exceeds the specified attempt limit, a **Trouble Logging In?** screen is displayed. This screen prompts the user to contact the Helpdesk to obtain a passcode.
{% endstep %}

{% step %}

#### Choose Helpdesk Code

Click the **Helpdesk Code**. The following screen is displayed. At this stage, reach out to your helpdesk admin to receive the code.&#x20;

The following table outlines what happens when you click each link:

| When you click...           | The UI                                                                      |
| --------------------------- | --------------------------------------------------------------------------- |
| Helpdesk code               | Takes you to the new screen to enter the code provided by Helpdesk.         |
| Return to all login options | Displays all the configured adaptive authentication journeys for that user. |
| {% endstep %}               |                                                                             |

{% step %}

#### Enter the bypass code

Enter the bypass code received from your helpdesk admin.
{% endstep %}

{% step %}

#### Login successful

Upon successful validation of the passcode, the Login successful message is displayed to the user.
{% endstep %}

{% step %}

#### Reset your MFA

The user is prompted to reset one of their authentication methods. The **Reset your MFA** screen is displayed only to users who:

* Have Behavioral Authentication and/or PIN authentication enabled in the configured authentication journey, and
* Have previously enrolled in those authentication methods.
  {% endstep %}

{% step %}

#### Select the method to reset

On the **Reset your MFA** screen, click the authentication method that needs to be reset. In this scenario, select **User PIN**.
{% endstep %}

{% step %}

#### Complete the reset

After selecting User PIN, the **Begin Setup** screen appears. The user must enter a new PIN and click Submit to complete the reset process.

Upon successful setup, the user is logged into the workstation.
{% endstep %}
{% endstepper %}

### Step 3: Generating Passcodes

Community Administrators or users with the **user.helpdesk-passcode.generate** permission can generate a passcode for users who contact the Helpdesk after behavioral authentication fails during workstation login. The passcode is a randomly generated six-digit number. The administrator can specify how long the passcode remains valid.

To generate a passcode from the AdminX interface:

{% stepper %}
{% step %}

#### Log in

Log in to your tenant as a community administrator.&#x20;
{% endstep %}

{% step %}

#### Open All Users

Navigate to **Users > All Users**.&#x20;
{% endstep %}

{% step %}

#### Generate Passcode

Click **Generate Passcode**.
{% endstep %}

{% step %}

#### Set the expiry

In the **Generate One-Time Passcode** screen, specify the duration after which the passcode will expire.

The duration can be specified in either minutes or hours.&#x20;

* Minimum duration: 1 minute
* Maximum duration: 24 hours
* Default duration: 10 minutes
  {% endstep %}

{% step %}

#### Generate

Click **Generate**.&#x20;
{% endstep %}
{% endstepper %}

### Event Logs

The following events are triggered as part of the Fallback Authentication workflow:

* **E\_FALLBACK\_AUTH\_CONFIGURED** – Triggered when fallback authentication settings are updated from the Windows MFA Settings page, such as enabling or disabling the feature or modifying the configured attempt threshold.
* **E\_FALLBACK\_JOURNEY\_CREATED** – Triggered when a new fallback authentication journey is created.
* **E\_FALLBACK\_JOURNEY\_MODIFIED** – Triggered when an existing fallback authentication journey is modified.
* **E\_FALLBACK\_JOURNEY\_DELETED** – Triggered when a configured fallback authentication journey is deleted.
* **E\_OTP\_REQUESTED** – Triggered when a request is made to generate a one-time passcode (OTP).
* **E\_OTP\_GENERATED** – Triggered when the OTP is successfully generated.
* **E\_OTP\_VERIFIED** – Triggered when the OTP verification process is completed, indicating whether the verification was successful or failed.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
