Centrally managed multi factor authentication for all your users' notebooks

In enterprises or organizations users and their 2nd factors are managed centrally by you, the IT department. This works fine with logins to central services like web portals, the VPN or your SSH servers.

But when it comes to the login at notebooks it comes to some additional challenges you need to overcome. Even in 2026 - notebooks can go offline.

There are many different technical ways for multi factor authentication with different underlying cryptographic mechanisms. Symmetic keys or assymmetic keys. Some can work offline, some are hard to manage, some do not work offline in a sensible way.
In this talk we are looking into different authentication mechanism be it x509 certificates, OTP or FIDO2 to name a few with their pros and cons.

Then we check how the open source multi factor management system privacyIDEA implements different ways of authenticating offline at your user's notebooks - be it Linux or Windows - with OTP tokens or with FIDO2 devices. In 2019 I held a talk at TXLF about privacyIDEA in general as an on prem multi factor solution. We are now looking deeper into management of FIDO2 devices and management for local logins to Linux and Windows machines.

You will get in depth knowledge how you can secure your notebooks with reliable authentication hardware like Yubikeys or other FIDO2 devices centrally managed in your own on prem privacyIDEA system.

Cornelius Kölbel

Cornelius is into multi factor authentication since 2004. He is the project lead of the MFA system privacyIDEA.

As a consultant Cornelius learnt to understand customers requirements in heterogeneous networks first hand. He planned and implemented several public key infrastructures for smartcard usage and was one of the first to work on the interoperability of the Aladdin eToken between Windows and Linux.

In 2006 he started one of the the first open source one time password systems implementing the HOTP algorithm. Three years later Cornelius initiated an enterprise OTP solution as product manager. In 2014 he kicked off the open source privacyIDEA project. It is a vendor independent authentication system, which can be used to manage arbitrary authentication objects to implement many different ways of multi factor authentication.

Cornelius spoke at several conferences in Germany, in Austria, in the Netherlands, in Belgium (FOSDEM), in Denmark and in the U.S.