No integration with a Physical Access Control System (PACS) is required for workstation authentication. Badge authentication is managed through TruU using the configured badge format and user mapping.
Minimum Requirements
1. Compatible Badge Reader
- Any PC/SC-compatible NFC badge reader that supports Keyboard Wedge Mode
- USB-connected badge reader
- The HID OMNIKEY 5427 G2 and HID OMNIKEY 5427CK have been validated and are the recommended readers
2. Windows Workstation
- Windows 10 or Windows 11
- TruU Shared Workstation installed
- Badge Authentication enabled through the Shared Workstation policy
3. Directory Integration
A supported identity directory must be connected to TruU. The directory is used to identify and authenticate users during sign-in. Examples include:- Microsoft Active Directory
- Microsoft Entra ID
- Other supported identity providers
4. Badge Configuration
Before badge authentication can be used:- Configure the badge card format in the TruU Admin Console so TruU can correctly interpret the badge data.
- Associate badges with users using one of the following methods:
- Manual Assignment: Assign the badge directly to the user in the TruU Admin Console.
- Directory Lookup: Store the badge identifier in a supported directory attribute (such as Active Directory or Microsoft Entra ID). During authentication, TruU automatically searches the configured badge attribute to identify the user.
- Enable Badge Authentication in the applicable authentication policy.
For step-by-step console configuration, see Configuring Physical Access Badge for Shared Workstation.
Authentication Flow
- The user presents an NFC badge to the badge reader.
- The badge reader sends the badge information to the Shared Workstation.
- TruU identifies the user based on the configured badge information.
- Shared Workstation evaluates the authentication policy.
- If required, the user is prompted for an additional authentication factor (for example, a PIN).
- The user is successfully signed in to Windows.

