For the complete documentation index, see llms.txt. This page is also available as Markdown.

Push Notification

Users receive an approval request on the 1Kosmos mobile app. From v2.0.4.0, a Number Challenge option is available to protect against push bombing attacks.

Push notification login user Journey

Admin Setup

Configure the Authentication Journey

  1. In AdminX, navigate to Applications > Windows MFA > Adaptive Auth Journeys.

  2. Create a new journey or edit an existing one.

  3. Under Authentication Method, select either:

    • Push Notification - push-only, no password required.

    • Password & Push Notification - password entered first, then push sent.

  4. Assign the journey to the target user group or machine policy.

  5. Save and publish the journey.

Enable Number Challenge

Number Challenge requires Credential Provider v2.0.4.0 or later. Ensure the agent is updated before enabling this toggle.

  1. In AdminX, navigate to Authentication > Passwordless Login > Passwordless Login using 1Kosmos App.

  2. Toggle Enable number challenge on all push notification requests to ON.

  3. Save the settings.

When enabled, all push notifications sent through any journey configured with Push Notification will include a number challenge.


User Guide

Standard Push Notification Login

  1. At the Windows login screen, click the 1Kosmos tile.

  2. If using the Other User tile, enter your username first.

  3. Select Push Notification from the available authentication options.

  4. A push notification is sent to your enrolled 1Kosmos mobile app.

  5. Open the notification and tap Yes, it's me.

  6. The Windows session unlocks and you are logged in.

The push notification expires after a fixed timeout. If not approved in time, the request cancels and you must initiate a new login attempt.

Push Notification with Number Challenge

  1. At the Windows login screen, click the 1Kosmos tile.

  2. If using the Other User tile, enter your username first.

  3. Select Push Notification from the available authentication options.

  4. A number is displayed on the Windows login screen.

  5. A push notification is sent to your enrolled 1Kosmos mobile app showing multiple numbers.

  6. In the app, tap the number that matches the number shown on the Windows screen.

  7. If the correct number is selected, the Windows session unlocks and you are logged in.

Behavior Comparison

Behavior
Number Challenge Disabled
Number Challenge Enabled

Interface on Windows login screen

No number displayed

A number is shown on screen

Interface on mobile app

"Yes, it's me" consent screen

Number selection screen with multiple options

Required user action

Tap Yes, it's me

Tap the number matching the Windows screen

Protection against push bombing

Not provided

Active - wrong number cancels auth immediately


Troubleshooting

Issue
Likely Cause
Resolution

Push notification not received

Mobile app not enrolled or disconnected; no device internet; OS notifications blocked

Verify mobile app is enrolled and connected; check device internet and notification permissions; ask user to open the app manually and check pending requests

Push notification expired

User did not respond within the timeout window

Initiate a new login attempt from the Windows login screen

Wrong number selected (Number Challenge)

User tapped incorrect number

Authentication is automatically cancelled; initiate a new login attempt; if recurring, verify no push bombing attempt is in progress

User tapped Cancel

User dismissed the notification intentionally or accidentally

Initiate a new login attempt; if recurring, check for unsolicited push notifications and report as a potential push bombing incident

Push received but app shows error

App version outdated; tenant connectivity issue

Update the 1Kosmos mobile app; verify tenant URL and connectivity from the mobile device

Last updated

Was this helpful?