> For the complete documentation index, see [llms.txt](https://docs.1kosmos.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.1kosmos.com/authentication/windows-workstation-mfa/release-notes-for-windows-workstation-mfa.md).

# Release Notes for Windows Workstation MFA

***

## Overview

Release notes for the 1Kosmos Workstation Login Credential Provider for Windows. Versions are listed in reverse chronological order, with the most recent release at the top.

{% hint style="info" %}
The Credential Provider was rebranded from "BlockID" to "1Kosmos" beginning in release 2.4.0.0. References to "BlockID" in earlier releases reflect the product naming at the time of release.
{% endhint %}

### 2.4.6.0

*July 17, 2026*

#### New Features

**MFA Support for Local Windows Users**

Community administrators can now enforce multi-factor authentication (MFA) for local Windows users. Previously, local users without an alias mapping bypassed all MFA and proceeded directly to password-only login.

When enabled, local users are required to complete MFA before entering their Windows password - online or offline. If a user is disabled on the platform, login is blocked.

{% hint style="info" %}
To enable this feature, reach out to your 1Kosmos representative.
{% endhint %}

**Configurable Maximum Offline PIN Attempts**

The maximum number of incorrect offline PIN attempts allowed before PIN input is disabled is now configurable. Previously, this was fixed at 3 attempts.

This setting is configurable via CaaS. If not configured, the default of 3 attempts applies.

**Computer Name Display During Local Account Login**

The login screen now displays the computer name when a local account login is detected. This helps IT administrators identify the machine without having to ask the user separately.

**Rate Limit Support for OTP and Push Notifications**

Rate limiting for OTP and push notifications is now extended to the Windows Credential Provider. When a user exceeds the allowed number of requests within a defined time window, the Credential Provider displays an error message indicating how long to wait before retrying.

The rate limit error message is supported in English, French, Spanish, Portuguese, and German.

**Improved Visibility into Workstation Lock Events**

Workstation lock events now include additional information to identify whether the lock was triggered automatically by the Windows Credential Provider, by the user manually, or due to inactivity.

Community administrators can navigate to events in the  AdminX interface to distinguish security-enforced locks from user-initiated or system locks.

**Configurable Pre-Lock Notification Countdown for Offline PIN Login**

The countdown duration before workstation lock on network restoration (introduced in Release v2.4.5) is now configurable. The notification message dynamically reflects the configured countdown value.

This setting is configurable via CaaS. If not configured, the default of 5 seconds applies.

#### Bug Fixes

* Fixed an issue where offline OTP validation failed when the username was entered in lowercase, while the same username in uppercase authenticated successfully.
* Fixed an issue where OS name and version fields in Windows Credential Provider login events displayed incorrect or inconsistent values.

### 2.4.5.0

*June 25, 2026*

#### New Features

**Complete Session Activity Tracking**

The Windows Credential Provider now captures and reports all session lifecycle events to the 1Kosmos platform, including login, unlock, workstation lock, and session logoff.

Previously, only authentication outcomes were reported. With this update, organizations can accurately monitor session activity across the full user lifecycle, supporting use cases such as auditing session behavior, calculating active versus inactive periods, and identifying productivity patterns.

Events are reliably delivered even across network interruptions, with offline events queued and emitted in chronological order once connectivity is restored.

**Enhanced Security During Offline PIN Login**

When a user logs in using offline PIN due to platform unavailability, the Windows Credential Provider now monitors for network restoration in the background. Once connectivity is confirmed, the workstation displays a notification and locks automatically, requiring the user to authenticate using the configured authentication journey.

Offline PIN login activity is now recorded and synchronized to the platform once connectivity is restored, closing the audit gap where offline logins were previously unrecorded.

#### Security Enhancements

* Strengthened filesystem permissions and access controls for privileged service communication, reducing the risk of unauthorized local access.
* Strengthened binary integrity protections for Windows authentication components, improving resistance to unauthorized modification.

### 2.4.4.0

*May 28, 2026*

#### New Features

**Multilingual Support for CP UI and Behavior Authentication**

The 1Kosmos Credential Provider now supports Spanish, Portuguese, French, and German. The Credential Provider automatically detects the Windows OS language setting on the user's workstation and displays the interface in the corresponding supported language, with no action required from the end-user.

Administrators can also enforce a specific display language across all managed devices, regardless of individual workstation locale settings.

**Microsoft TPM Virtual Smart Card Support for Windows Login**

The 1Kosmos Credential Provider now supports Microsoft TPM Virtual Smart Card (VSC)-based authentication, improving Windows passwordless login performance in shared workstation environments.

Previously, authentication times were approximately 20 seconds per login. With TPM VSC support enabled, user certificates are securely cached in the device TPM after the initial login, reducing subsequent login times to approximately 3 to 4 seconds.

If TPM hardware is unavailable or initialization fails, authentication automatically falls back to the existing 1Kosmos login flow, ensuring uninterrupted access.

### 2.4.3.0

*May 19, 2026*

#### Bug Fixes

**Force Enrollment for Behavior Auth and PIN**

Fixed an issue where users could bypass Behavior Auth and PIN enrollment by clicking a "Skip Enrollment & Login" link on the enrollment screens. Organizations requiring all users to enroll were affected as this allowed users to proceed without setting up their authentication factors.

Administrators can now enforce mandatory enrollment, ensuring users complete setup before logging in. This setting is configurable via CaaS.

**Case-Insensitive Username for Offline Authentication**

Fixed an issue where offline authentication failed when the username was entered in a different case than what was registered. For example, a user registered as "JohnDoe" would fail authentication when typing "johndoe" or "JOHNDOE".

Offline authentication now performs case-insensitive username comparison, consistent with standard Windows login behavior. No configuration is required.

### 2.4.2.0

*May 12, 2026*

#### Enhancements

**LiveID authentication performance optimization.** This release significantly reduces delays during camera initialization and login for the LiveID authentication flow.

Impact:

* Camera initialization reduced from approximately 8 seconds to 4–5 milliseconds.
* Approximately 99.9% performance improvement.
* Faster and more consistent login experience.

{% hint style="info" %}
Smartcard and PKINIT login latency depend on Windows processing and network conditions and are not impacted by this change.&#x20;
{% endhint %}

**Security fixes.** Additional security enhancements have been implemented to strengthen protection in the Windows Workstation MFA Agent.

### 2.4.0.0

*March 31, 2026*

#### New Features

**Rebranding to 1Kosmos.** The Windows Workstation MFA Agent has been rebranded to align with the updated 1Kosmos brand identity. All user-facing references to "BlockID" have been replaced with 1Kosmos branding.

Key changes:

* Removal of "BlockID" terminology across the Credential Provider.
* Updated logos and visual elements with 1Kosmos branding across login screens, dialogs, and configuration interfaces.

**Dependency check enhancement for the installer.** Enhanced dependency validation has been added to the EXE installer, which now checks for required .NET Framework versions and automatically installs missing dependencies during setup.

The 1Kosmos Credential Provider continues to support two installation formats:

* **EXE installer** - Performs dependency checks and automatically installs missing prerequisites (such as .NET Framework 4.8).
* **MSI installer** - Requires all prerequisites to be installed manually. If dependencies are missing, the installation will not proceed.

{% hint style="warning" %}
Ensure required dependencies are installed before using the MSI installer.
{% endhint %}

**Kerberos service ticket retrieval fix.** Fixed an issue where Kerberos service ticket retrieval failed after login when the smart card was ejected. The Credential Provider now supports configurable smart card ejection behavior to maintain credential context.

The following registry settings are available to control smart card ejection behavior (default: enabled):

* `DisableSmartcardOnLogin` (DWORD) — default: 1
* `DisableSmartcardOnCredUI` (DWORD) — default: 1

**LiveID performance enhancement — early camera warm-up.** Implemented early camera initialization for LiveID authentication to reduce authentication time and improve user experience.

Benefits:

* Faster authentication response time.
* Reduced wait time for biometric authentication.

#### Bug Fixes

* Fixed an issue where PIN-based login was not functioning correctly when the machine was offline and Behavioral Authentication was configured.

### 2.3.0.0

*March 18, 2026*

#### New Features

**MSI-based installation support.** The V2 Credential Provider can now be installed using an MSI package, enabling both interactive (UI-based) and silent installations. For more information, see [Installation Using MSI Package.](/authentication/windows-workstation-mfa/installation/install-using-msi.md)

### 2.2.0.0

*March 13, 2026*

#### New Features

**Prevent workstation lockouts with helpdesk passcode fallback.** Users who fail to authenticate through Behavioral Authentication + PIN after a configurable number of attempts can now access a fallback authentication journey to regain access to their Windows workstation. In this flow, users contact the Helpdesk to obtain a temporary passcode, allowing them to securely complete login, reduce the risk of being locked out, and maintain productivity.

After retrieving the passcode, users can either log in directly or reset one enrolled authentication factor (Behavioral Authentication or PIN), if enabled and allowed for their account.

Community administrators must configure the fallback authentication journey in AdminX and ensure a primary authentication journey (for example, Behavioral Authentication + PIN, or Password + OTP) is configured. If no authentication journey is defined, the fallback option will not be presented to users. For more information, see[ Fallback Authentication](/authentication/windows-workstation-mfa/authentication-methods/fallback-authentication.md).

{% hint style="info" %}

* Supported authentication factors: Behavior Authentication, PIN, and OTP.
* Supported Credential Provider version: 2.2.0.0.&#x20;
  {% endhint %}

**Offline authentication for users without mobile OTP.** Windows workstation users who do not have access to a mobile device or camera can now authenticate using a locally stored PIN when offline. This enables secure workstation access without requiring the 1Kosmos mobile app or network connectivity.

When the device is offline, the Credential Provider detects the loss of connectivity and presents available authentication options based on what is cached on the device:

* PIN login, if a PIN is cached.
* OTP login, if a CommunitySeed is available.
* Both options, if both are available.

For security, offline PIN authentication allows a maximum of three attempts. After the third failed attempt, the cached PIN is cleared, and the user must reconnect to the internet to authenticate.

### 2.1.5.3

*February 14, 2026*

#### New Features

**Registry-based switches to disable the 1Kosmos Credential Provider.** Administrators can now dynamically disable the v2 Credential Provider without requiring uninstallation. Two new registry-based configuration switches control the visibility of the 1Kosmos Credential Provider during specific authentication flows.

New registry settings:

* **`Disable1KosmosOnLogin`** — when set to `1`, the 1Kosmos Credential Provider is hidden during login and unlock flows.
* **`Disable1KosmosOnCredUI`** — when set to `1`, the 1Kosmos Credential Provider is excluded from CredUI flows and will not appear in credential prompts.

Impact:

* No system restart or uninstallation is required to disable the Credential Provider.
* Provides administrators with greater operational flexibility.
* Ensures non-disruptive fallback to other credential providers when disabled.

### 2.1.5.2

*January 28, 2026*

#### Enhancements

**Enhanced `installer.exe` with custom command-line configuration support.** The Windows Workstation MFA Agent installer now supports custom configuration through command-line parameters during automated installation. This enhancement eliminates the need for external batch (BAT) scripts previously used to modify registry values and copy configuration files post-installation. By applying configuration directly during installation, the process is now more streamlined and secure.

For more information, see[ Installation Using Command-Line Parameters.](/authentication/windows-workstation-mfa/installation/install-using-exe-legacy.md)

### 2.1.5.1

*January 8, 2026*

#### Bug Fixes

* Fixed an issue that prevented users from being signed in to Windows after successful LiveID face authentication.
* Enhanced user validation during mobile authentication to ensure consistent behavior across all environments.

### 2.1.5.0

*November 26, 2025*

#### New Features

**Support for password-based shared account access.** Users who decline biometric consent can now authenticate on shared workstations using their primary account password. Once authenticated, they can select a shared account as before. Administrators can enable this through the new **Password for Shared Account Login** option in Windows MFA. For more information, see [Password-Based Authentication for Shared Accounts.](/authentication/windows-workstation-mfa/deployment-scenarios/shared-workstations.md)

{% hint style="warning" %}

* Users must upgrade their Windows Workstation MFA Agent to version 2.1.5.0 for this feature to function.
* The existing FIDO shared account login journey must be re-saved to ensure compatibility with the new Windows Workstation MFA Agent.&#x20;
  {% endhint %}

**PIN lockout notifications.** The Windows Workstation MFA Agent now provides clear notifications when the behavior authentication PIN becomes temporarily locked after repeated incorrect attempts:

{% hint style="info" %}
*"Your PIN has been locked due to multiple incorrect PIN attempts. You can attempt using your PIN in x minutes."*
{% endhint %}

These updates help users better understand lockouts and reduce login confusion.

**Username displayed in UWL2 session.** Previously, during login, users could see a different persona in the mobile app than the username they were attempting to authenticate, because the Windows Workstation MFA Agent did not send the requested username to the app. This could make it appear as though authentication had occurred for the wrong user. The UWL2 session now includes the username being authenticated and identifies the session as an authentication request, ensuring the mobile app displays the correct user during login.

### 2.1.4.0

*November 7, 2025*

#### Enhancements

* Added detailed FIDO-related debug logs to assist in troubleshooting and observability. A new log file, **`BlockIDFIDOLogs.txt`**, is now created in the Logs folder.
* Security enhancements have been implemented to improve protection and strengthen overall system resilience in the Windows Workstation MFA Agent.

#### Bug Fixes

* Fixed an issue where the BlockID Credential Provider would not appear as an available option on the LogonUI screen after the workstation resumed from sleep.
* Fixed an issue where, during RDP login, the message "Something went wrong. Please contact your administrator." was displayed after entering the password in the Microsoft native Credential Provider and submitting the OTP in the 1Kosmos Credential Provider.

### 2.1.3.0

*October 17, 2025*

#### New Features

**Support for filtering the password provider in the Windows Workstation MFA Agent.** Administrators can now independently enable or disable the password provider for Login/Unlock and CredUI flows, allowing MFA to be enforced at the workstation login screen while retaining password-based access where still required (for example, RDP and Run As). For more information, see [Configuring Password Provider Visibility.](/authentication/windows-workstation-mfa/authentication-methods/run-as-and-uac.md)

**Ability to clear the last-used provider.** The Windows Workstation MFA Agent can now prevent the OS from automatically selecting the last-used credential provider on subsequent logins, allowing users to choose a different provider or delay login.

**Request ID in logging.** Added support for displaying `requestId` in system logs to improve traceability and debugging.

#### Bug Fixes

* Fixed an issue where the screen flickered during window transitions, resulting in a poor user experience.
* Fixed a crash in the Windows Workstation MFA Agent when logging in with a local user that shares the same username as a directory user.
* Fixed an issue causing frequent `LogonUI.exe` crashes in Jefferies VDI environments following the BlockID Credential Provider upgrade. The crashes were due to invalid memory access within the Credential Provider module during user logon.

### 2.1.2.0

*September 5, 2025*

#### New Features

**Enroll and authenticate to Windows using typing biometrics and PIN.** Two additional authentication factors are now supported:

* **Behavior Authentication** — recognizes a user by their unique typing rhythm, speed, and key-press patterns. This helps verify identity without additional credentials.
* **User PIN** — allows a user to set and use their own Personal Identification Number.

Both can be enrolled through the Windows Workstation MFA Agent and used as authentication methods for logging in to Windows.

This is particularly beneficial in environments where login requires DSS-compliant passwords (14–16 characters), which can be difficult to remember. Users can also enroll a PIN as an additional measure to authenticate and log in to their workstation securely. By reducing the need for frequent password changes, this feature offers a more seamless authentication experience. For more information, see [Behavior Authentication](/authentication/windows-workstation-mfa/authentication-methods/behavior-authentication.md).

**Security enhancement — authenticated JWT for SCEP and enrollments.** The platform now provides the Windows Workstation MFA Agent with a JWT containing all the completed authentication factors for the user. This JWT is then used to fetch SCEP or for enrollment.

**Enhanced Generate OTP API.** The Windows Workstation MFA Agent now supports OTP generation via Email, SMS, and Voice when a user's mobile device is not registered or enrolled.

### 2.0.9.0

*June 30, 2025*

#### New Features

* Shared account logins now use the username fetched from the CyberArk proxy, instead of relying on the displayed username on the shared account window. The CyberArk proxy applies a transformation script to retrieve the username in UPN format.

#### Bug Fixes

* Fixed an issue where Windows LiveID incorrectly validated a face even when it was placed outside the camera view.

### 2.0.8.0

*May 15, 2025*

#### New Features

**Support for MFA on local account logins.** The Credential Provider now supports displaying multi-factor authentication (MFA) methods for both local and remote account logins. To enable MFA for a local user, the local account must be added as an alias. For more information, see[ Offline Login.](/authentication/windows-workstation-mfa/deployment-scenarios/offline-scenario.md)

**Introduced CyberArk Proxy component.** Previously, the Windows Workstation MFA Agent sent requests directly to CyberArk to retrieve service account credentials. Under high concurrency (approximately 400 users), the service account would become locked out due to CyberArk throttling, causing login disruptions. Even at lower loads, API throttling produced slow response times (approximately 5 seconds), negatively impacting user experience and business continuity.

To address this, 1Kosmos has introduced a new on-premises proxy component for Windows, macOS, and Linux systems. The proxy handles the connection to CyberArk, offloading direct API calls from each workstation. On Windows it runs as a service; on macOS and Linux it operates via the command line. Before starting the service, administrators must configure CyberArk credentials, including a valid service account, to streamline password retrieval and prevent repeated logins. For more information, see [CyberArk Proxy Login Using Shared Accounts.](/authentication/windows-workstation-mfa/deployment-scenarios/shared-workstations.md)

{% hint style="info" %}
Both direct and proxy-based implementations are supported. Customers can choose the model that best fits their environment.&#x20;
{% endhint %}

#### Security

* Addressed a potential replay attack vector in which an attacker with physical access to a workstation could intercept and replay API responses from the platform to gain unauthorized access. The scenario required the attacker to install a proxy tool on the target machine to capture network traffic, making it a complex and unlikely attack path. Safeguards have now been implemented to mitigate this risk and enhance overall platform security.

#### Bug Fixes

* Resolved an issue where cURL requests had inconsistent timeout behavior on the loading screen:
  * When internet connectivity was available, requests timed out as expected.
  * When a proxy was enabled but no internet connection was present, requests experienced prolonged delays.

### 2.0.7.0

*May 1, 2025*

#### New Features

**Passwordless authentication for RDP and Run As use cases.** Users can now authenticate passwordlessly when running applications as an administrator or as a different user.&#x20;

**Login to Windows using UserPrincipalName (UPN).** User login is now supported using both the SAM account name and the User Principal Name (UPN). To enable UPN-based login, administrators must map the user's SAM account name to the BlockID attribute (`winuserattribute`).

**Enhanced `E_LOGIN_SUCCEEDED` and `E_LOGIN_FAILED` event details.** When a user logs in via QR, Push, or FIDO mechanisms, both events now include device details and the authenticator used during authentication:

* `device_id`
* `auth_device_os`
* `auth_device_name`
* `auth_device_app_name`
* `auth_device_app_version`
* `auth_device_ip_address`
* `auth_device_os_type`
* `auth_device_make`
* `auth_device_model`

#### Miscellaneous

* During installation of the Windows Workstation MFA Agent, the default idle timeout value has been updated to 75 seconds to enhance session security and responsiveness.

### 2.0.6.0

*February 24, 2025*

#### New Features

**Send OTP via SMS, email, and voice call.** Users are now shown options to send OTP via SMS, email, or voice call if their profile has an associated phone number and/or email address.

{% hint style="info" %}

* The phone number used for SMS and voice call is the primary phone number associated with the profile.
* OTP delivery via these channels is enabled by default. Voice call and SMS options are displayed if a phone number is associated with the user profile; email OTP is shown if an email address is associated.
* No control over enabling individual SMS, email, or voice OTP options is currently available.&#x20;
  {% endhint %}

#### Miscellaneous

* Added a feedback message for users after a QR code is scanned and authentication is approved on the mobile device.
* Added a feedback message to inform users when their account is locked due to exceeding the maximum number of incorrect OTP entries.

#### Bug Fixes

* Resolved an issue where FIDO login would occasionally fail.

### 2.0.5.0

*December 20, 2024*

#### New Features

**Notifying users during QR scan validation.** When users scan the QR code on the login screen, the Windows Workstation MFA Agent now informs them that the scanned QR code is being validated, providing a smoother user experience.

**Enhanced logging for PII protection.** Logs have been updated to prevent the display of users' PII data.

**Error message on maximum incorrect OTP attempts.** The Windows Workstation MFA Agent now displays an error message when a user exceeds the maximum number of incorrect OTP attempts, notifying them that the account is locked and they can try again later.

#### Bug Fixes

* Fixed an issue where users were unable to log in to the workstation with a registered FIDO key.
* Fixed an issue where log files were being created in the default location despite a custom install path being selected.

### 2.0.4.0

*December 13, 2024*

#### New Features

* Support for the new consent screen on mobile.
* Support for number-challenge push notifications.
* Custom branding capability.
* Support for direct upgrade from V1 to V2 Credential Provider.
* Miscellaneous UI-related bug fixes.

### 2.0.3.1

*October 12, 2024*

#### Bug Fixes

* Fixed an issue where smartcard login via BlockID (for example, Push) failed after session lock in Citrix VDI environments with V2 Credential Provider 2.0.3.0, displaying "The username or password is incorrect" after a prolonged loading screen.

### 2.0.3.0

*September 30, 2024*

#### New Features

* Support for local account login.
* Support for shared accounts.
* Stability improvements and UX fixes.

### 2.0.2.0

*August 30, 2024*

#### New Features

**Allow local accounts to log in to the workstation.** Users can now log in to a workstation using a local account through the BlockID app. The Credential Provider intelligently identifies whether the selected account is a local account or a domain account. This enables workstation access without requiring a network connection and provides flexibility and resilience, ensuring users have reliable access under a variety of circumstances.

**Determine users using shared accounts in the V2 Credential Provider.** The Windows V2 Credential Provider has been enhanced to identify the user behind a shared account login. A new **Shared Account** option has been added to the Sign In — Choose an Authentication Method screen. The Shared Account option must be configured in the database. When a user selects this option, a list of shared accounts associated with the user is displayed; the user can then choose the appropriate account and log in. This enables organizations to trace which user is operating a shared account and helps with shared-account management.

### 2.00.00

*July 10, 2024*

#### New Features

* Introduced a new Credential Provider built on the Windows Credential Provider V2 framework, enabling user authentication using a combination of password and one-time passcode (OTP). For more information, see [Windows Workstation MFA Agent.](/authentication/windows-workstation-mfa/overview.md)

### 1.09.01

*March 22, 2024*

#### New Features

* Enabled password redirection from the host workstation, allowing OTP, QR, and Push mechanisms to be used on a remote machine when connecting through RDP.
* OTP and FIDO options have been integrated into the **Switch User** lock screen. BlockID now supports Push notifications, OTP, and FIDO keys for unlocking the workstation.

#### Bug Fixes

* Fixed an issue where multiple QR dialogs would appear on the login screen on some workstations.
* Fixed an issue where cancellation of QR and Push notification would not work in certain cases.

### 1.09.00

*January 31, 2024*

#### New Features

* Introduced functionality for using password and OTP MFA through the **More choices** option on the Windows authentication prompt for applications.
* Added the ability to pre-populate passwords on the remote workstation's login screen when password redirects occur from the host workstation.

#### Enhancements

* QR and Push notification login mechanisms are now configurable, allowing users to easily enable or disable these features as needed.
* The OTP mechanism is now accessible on the Windows lock screen. Users can enable this from the BlockID Configurator.
* The automated installation script has been updated to accommodate the new configurations introduced.

### 1.08.07.01

*November 22, 2023*

#### Enhancements

* Removed validations on the tenant tag in the BlockID Configurator.
* Resolved an issue where the BlockID Credential Provider would crash when an invalid user attempted to log in with a FIDO key.

### 1.08.07

*October 19, 2023*

#### Enhancements

* Eliminated the requirement for an initial mobile login as a prerequisite for enabling authentication through FIDO keys. Because the FIDO assertion is produced using the 1Kosmos platform, the workstation must be connected to the internet to use this feature.
* Added configuration to enable or disable the PIN prompt for FIDO key logins on the lock screen.
* Updated the behavior of the UV and UP flags for FIDO login on the Credential Provider based on the configuration received from the API.

### 1.08.06

*September 21, 2023*

#### Bug Fixes

* Cross-signed the Credential Provider DLLs through Microsoft. This was required to resolve an issue on Windows 11 22H2 workstations where LSA, when enabled, would block the 1Kosmos smartcard driver from loading, resulting in authentication failures.

### 1.08.05

*August 31, 2023*

#### Bug Fixes

* Resolved an issue where logins would fail because the communication protocol was not initialized in certain situations. This issue was intermittent, and users would see a generic Windows OS error message: **Username or password is incorrect**.

### 1.08.04

*August 10, 2023*

#### Enhancements

* Implemented a cache manager to better manage the local cache. The cache manager handles the API endpoint caching and associated public keys for a maximum of 24 hours, improving overall performance and login time.

### 1.08.03

*July 20, 2023*

#### Enhancements

* Smart Card Driver DLL files are now signed using a new code-signing certificate.
* Logging functionality in the BlockID Credential Provider has been expanded.
* Updated logic to identify PAC URLs. URLs are now treated as PAC URLs if the address contains `.pac`. This allows the BlockID Credential Provider to recognize PAC URLs that also have a policy parameter — for example, `http://webproxy.local:3128/proxy.pac?p=15df7tpd5` is now recognized as a PAC URL by the Credential Provider.

#### Bug Fixes

* Corrected a bug where a connection check through the proxy was not taking place.

### 1.08.00

*May 18, 2023*

#### Enhancements

* Added a timeout to the BlockID Credential Provider when establishing a connection through a proxy to check system connectivity status and refresh login tiles.

#### Bug Fixes

* Fixed an issue where remote connections through BlockID RDPHelper were failing.

### 1.07.05

*April 27, 2023*

#### New Features

**FIDO2-based authentication using security keys.** FIDO2 authentication using hardware security keys (for example, YubiKey) has been added to the BlockID Credential Provider. Users can enroll their security key using the AdminX control panel. When using FIDO2 login, the Credential Provider sends a FIDO challenge to the security key using the CTAP2 protocol. The Credential Provider validates the signed challenge returned by the key and allows the user to log in after successful verification.

#### Enhancements

* Updated the label for passwordless login using QR to **QR Login** and resized the dialog for a better user experience.

#### Bug Fixes

* Fixed an issue where BlockID Credential Provider smart card login was failing intermittently.

### 1.07.04

*February 17, 2023*

#### Enhancements

* The BlockID Credential Provider now caches service directory endpoints to avoid making repeated API calls for fetching data, improving overall performance and login time.

#### Bug Fixes

* Fixed an issue where the BlockID Credential Provider tiles were repeating in cases of multiple user logins through RDP on the same workstation.

### 1.07.03

*January 25, 2023*

#### Enhancements

* Users can now choose whether to enable or disable automatic restarts for workstations when installing the BlockID Credential Provider using batch scripts. Users can opt to restart the workstation by supplying a restart flag.
* BlockID now has a setting to configure **Login with FIDO** mode. Configuration for this setting can also be automated when running the installation and configuration script.
* The BlockID Credential Provider now updates its available login options when detecting a change in internet connectivity. When online, QR Code and Push Notification login options are available; when offline, only OTP login (if enabled in the BlockID Credential Provider) is available.

#### Bug Fixes

* Removed test-suite executables `FakeWinlogon.exe` and `NativeLibTest.exe` from the BlockID installer package. These simulators served no purpose to end users and have been removed.
* Fixed an issue where offline authentication using OTP failed after a proxy was set.
* Fixed an issue where the BlockID service did not start, causing the workstation screen to blur and rendering the login page inaccessible.

### 1.07.02

*December 7, 2022*

#### New Features

**FIDO2-based authentication for the BlockID Credential Provider.** FIDO2-based authentication has been integrated into the BlockID Credential Provider. Users can now enroll using the BlockID Mobile Application. With FIDO2 login, the BlockID Credential Provider sends a FIDO2 challenge to the BlockID Mobile Application for signing. The Credential Provider then validates the signed challenge, and after successful account verification, the user is logged in.

#### Enhancements

* BlockID now checks the expiration time of cached user certificates before authenticating the user when the machine is offline.

#### Bug Fixes

* Fixed an issue where proxy settings were not being used when creating new user sessions.
* Fixed an issue where the BlockID tile did not appear on the login screen when the VC++ Redistributable package was not installed on the workstation.

### 1.07.01

*September 1, 2022*

#### New Features

**Forced passwordless authentication.** Administrators can now enforce passwordless authentication on workstations. This disables the default password provider, leaving users with the option to log in via QR, Push notifications, OTP, and MFA. Forced passwordless can be enabled using the **Disable Windows Password Provider** option in the Advanced tab.

**CAD (Ctrl+Alt+Delete) requirement.** Requiring CAD (Ctrl + Alt + Delete) before sign-in ensures communication through a trusted path when credentials are provided, protecting users from attacks that attempt to intercept credentials at sign-in. This can be enabled using the **Enforce Ctrl + Alt + Del** option in the Advanced tab of the BlockID Configurator. CAD is enabled by default when the forced passwordless option is enabled.

#### Enhancements

* Ability to re-initialize QR or Push notification after an error or when the user cancels the login attempt.

#### Bug Fixes

* Fixed an issue where MFA (username + password + OTP) would not work in certain cases when the workstation was offline.

### 1.07.00

*August 22, 2022*

#### Enhancements

* The BlockID Credential Provider now caches the session's services and community public keys to avoid making repeated API calls for fetching them. This improves overall performance when using the platform microservice for user sessions.
* The BlockID Credential Provider now verifies whether the user account is linked to the DID.

### 1.06.02

*August 1, 2022*

#### New Features

**MFA login (User ID + Password + OTP).** The BlockID Credential Provider now supports using the password factor along with OTP for added security. Users are challenged for their username, password, and Workstation OTP (from the BlockID mobile app). This can be enabled using the **Allow Password Factor** setting in the BlockID Configurator.

**Support for BlockID OTP from the BlockID mobile app.** Users can now log in to their workstations using the BlockID OTP displayed on the main screen of the BlockID Mobile App. BlockID OTP is available by default and can be used when the workstation is online. If the administrator enables hardware tokens for OTP generation, this feature can be disabled.

**Support for hardware OTP tokens.** BlockID can now be configured to use OTPs from enterprise-issued hardware tokens such as OneSpan. This is enabled using the **Use Hardware OTP** setting in the BlockID Configurator. Hardware OTP authentication is available only when the workstation is online.

#### Enhancements

* **Support for UWL 2.0 sessions** — internal enhancement in which the BlockID Credential Provider uses the platform microservice for user session generation. This enables and supplements the audit trail of user activity.

#### Bug Fixes

* Fixed an issue where users could not cancel QR or Push notification on workstations or remote machines running Windows Server 2012 and Windows 8/8.1.

### 1.06.01

*May 30, 2022*

#### New Features

**Online login supported via OTP.** BlockID has extended the OTP authentication feature for use when the workstation is online. The setting can be enabled by the administrator using the **Enable Online OTP** setting in the BlockID Configurator. The Workstation OTP available in the BlockID App can be used to generate the time-based OTP for login. Users now have the choice of QR, Push notification, and Workstation OTP for logging in.

#### Enhancements

* BlockID now has configurations to enable Offline and/or Online OTP modes, as well as the ability to add custom images and labels for the OTP tiles on the login screen. These configurations can also be automated using the installation and configuration script.
* Updated icons for the Configurator, RDPHelper, and installer EXE.

### 1.06.00

*May 13, 2022*

#### New Features

**Offline login supported via OTP.** The BlockID Credential Provider now supports login via OTP as the authentication factor when the workstation is offline. BlockID detects when the workstation is not connected and challenges the user to enter the Workstation OTP from the BlockID mobile application. To use the Workstation OTP, the user must have logged in using BlockID QR or Push notification at least once previously.

#### Deprecated Functionality

* Deprecated the reverse QR scanning feature for offline login.

### 1.04.00

*August 16, 2021*

#### Bug Fixes

* Removed the "BlockID Initialization..." message on Windows start-up. Previously, if the service did not start during machine start-up for a considerable time, the Credential Provider waited with this message, which could incorrectly suggest that the delay was caused by BlockID.

### 1.03.01 — MSI

*July 19, 2021*

#### New Features

**Install BlockID via GPO.** An MSI file was added alongside the existing BlockID Credential Provider installation executable. This enables administrators to install BlockID via GPO.

### 1.03.01

*June 11, 2021*

#### New Features

**Optional deny credential passthrough for RDP.** A flag was added to the BlockID Configurator to deny credential passthrough for RDP connections. When the flag is checked, credentials passthrough is disabled on the remote machine (RDP). New configuration to deny credential passthrough has been added to the automatic installation and configuration script.

**Disabled default Windows Smart Card Credential Provider in the registry.** The default Windows smart card credential provider has been disabled in the registry to prevent users from using PIN on remote workstations to log in when using RDP.

### 1.03.00

*April 17, 2021*

#### Bug Fixes

* Fix to pass credentials in case of RDP login using username/password and to stop the BlockID QR pop-up.

#### Documentation Updates

* Versioning of the Credential Provider has been moved to a new format representing the quarterly release numbers.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.1kosmos.com/authentication/windows-workstation-mfa/release-notes-for-windows-workstation-mfa.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
