ATKey.LCM User Guide

ATKey.LCM integrates with Microsoft Entra ID, enabling credential lifecycle management in cloud-first and hybrid deployments.

Current Version: 0.0.14
Login Here

IMPORTANT:
In order to use ATKey.LCM the account logged in must be an Entra ID Global Administrator or an Authentication Administrator.
Authentication Administrators also require Cloud Application Administrator or Application Administrator roles to manage ATKey.LCM.

Important Concepts

ATKey.LCM System Architecture

ATKey Serial Number

Each ATKey.Pro and ATKey.Card NFC are trackable through a hexadecimal 8 digits code which is the serial number. Each serial number is unique to one key. The serial number is embedded in the key firmware, as well as printed on the key surface.

Through the serial number it can be traced key production, features, and shipment.

In ATKey.LCM serial numbers and Entra ID users IDs are paired for improved tracking.

ATK.LCM Onboarding

Set up ATKey.LCM for your organization and connect it with Entra ID in less than 10 minutes

Register your account

  • Visit ATKey.LCM at (https://atkey-lifecycle.authentrend.com/) and use the referral code your partner shared with you.

  • Use Entra ID and a Microsoft account to login.

    • Entra ID Global Admin or Authentication Administrator (+ Cloud Application Administrator or Application Administrator) role required to use ATKey.LCM.

  • You will be prompted to provide a support email and enter any referral code you may have.

  • ATKey.LCM will require you login into Entra ID and to grant API permission in order to work.

ATKey.LCM Overview

Dashboard

Upon login you will see the main dashboard.

Here is where you can see the deployment and usage of ATKeys at a glance.

The main metrics shown here are:

  • Number of active ATKeys

  • Number of accounts in your Entra ID organization

  • Number of credentials issued through ATKey.LCM

  • Number of free ATKeys

  • Status of the ATKeys registered


User List

The second tab is the full list of the accounts in you Entra ID environment.

For each account you can check to which departments they belong, what their role and which ATKeys are assigned to them.
You can leave notes for future reference.


ATKey Inventory

The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.

Keys details include:

  • Serial number

  • Model

  • Status (free, assigned, lost)

  • When it was first registered

  • When was activated

  • Last use

Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.


ATKey Inventory

The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.

Keys details include:

  • Serial number

  • Model

  • Status (free, assigned, lost)

  • When it was first registered

  • When was activated

  • Last use

Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.

Pre-Registration Tool

  • Visit the download tab in the ATKey.LCM interface. Is the fifth from the top on the left side panel.

  • Download the Admin Credential Pre-reg Tool

  • Install ATKey.LCM Pre-Reg.

    • At launch remember to use “Run as an administrator” otherwise the tool would not work.

Due to the Microsoft API limitation:

  • Admin cannot assign keys to their own account.

  • Authentication Administrators cannot assign keys to Global Administrators (the reverse is allowed).

Pre-reg Tool Flow for Admin

Add Workflow – Define Organization Key Policy

  • On opening the Pre-Reg Tool, click on Add Workflow. A new pop up will appear.

  • Name your workflow. You can set the pin to be randomly generated or to a default one. Here you can also establish how long the PIN should be, and if the user will have to change it on the first usage.

  • You can also establish a fingerprint policy such as requiring the user to register one at the next use.

  • Save your workflow to add it to the list of workflows available.

Pre-reg ATKey to Entra ID

  • Pick the workflow you want to run.

  • The system will prompt you with three possibilities:

    • To pre-reg an ATKey for each user

    • To pre-reg multiple keys to a single account (useful to have both a main and a backup key prepared or for accounts that are shared among multiple people)

    • To pre-reg all the selected accounts to a single key (useful for users that need access to multiple accounts)

  • After choosing the modality you will need to select the users you want to register the keys to. The pre-reg tool will show you all the users in your Microsoft environment. you can pick up to 20 users for each cycle.

  • After the users is time to map them to the ATKeys. Make sure they are connected to the computer. To map them just order them in front of the account they need to be connected with.

  • Once started the pre-reg process will ask if you want to add any of the key not already registered in ATKey.LCM and will require you to touch or click each key depending on the model when requested to complete the process.

    • If you are pre-registering ATKey.Card NFC, you will be prompted to remove it and reconnect it with the reader when the credential assignment process begins.