ATKey.LCM User Guide
ATKey.LCM integrates with Microsoft Entra ID, enabling credential lifecycle management in cloud-first and hybrid deployments.
Current Version: 0.0.14
Login Here
IMPORTANT:
In order to use ATKey.LCM the account logged in must be an Entra ID Global Administrator or an Authentication Administrator.
Authentication Administrators also require Cloud Application Administrator or Application Administrator roles to manage ATKey.LCM.
Important Concepts
ATKey.LCM System Architecture
ATKey Serial Number
Each ATKey.Pro and ATKey.Card NFC are trackable through a hexadecimal 8 digits code which is the serial number. Each serial number is unique to one key. The serial number is embedded in the key firmware, as well as printed on the key surface.
Through the serial number it can be traced key production, features, and shipment.
In ATKey.LCM serial numbers and Entra ID users IDs are paired for improved tracking.
ATK.LCM Onboarding
Set up ATKey.LCM for your organization and connect it with Entra ID in less than 10 minutes
Register your account
Visit ATKey.LCM at (https://atkey-lifecycle.authentrend.com/) and use the referral code your partner shared with you.
Use Entra ID and a Microsoft account to login.
Entra ID Global Admin or Authentication Administrator (+ Cloud Application Administrator or Application Administrator) role required to use ATKey.LCM.
You will be prompted to provide a support email and enter any referral code you may have.
ATKey.LCM will require you login into Entra ID and to grant API permission in order to work.
ATKey.LCM Overview
Dashboard
Upon login you will see the main dashboard.
Here is where you can see the deployment and usage of ATKeys at a glance.
The main metrics shown here are:
Number of active ATKeys
Number of accounts in your Entra ID organization
Number of credentials issued through ATKey.LCM
Number of free ATKeys
Status of the ATKeys registered
User List
The second tab is the full list of the accounts in you Entra ID environment.
For each account you can check to which departments they belong, what their role and which ATKeys are assigned to them.
You can leave notes for future reference.
ATKey Inventory
The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.
Keys details include:
Serial number
Model
Status (free, assigned, lost)
When it was first registered
When was activated
Last use
Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.
ATKey Inventory
The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.
Keys details include:
Serial number
Model
Status (free, assigned, lost)
When it was first registered
When was activated
Last use
Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.
Pre-Registration Tool
Visit the download tab in the ATKey.LCM interface. Is the fifth from the top on the left side panel.
Download the Admin Credential Pre-reg Tool
Install ATKey.LCM Pre-Reg.
At launch remember to use “Run as an administrator” otherwise the tool would not work.
Due to the Microsoft API limitation:
Admin cannot assign keys to their own account.
Authentication Administrators cannot assign keys to Global Administrators (the reverse is allowed).
Pre-reg Tool Flow for Admin
Add Workflow – Define Organization Key Policy
On opening the Pre-Reg Tool, click on Add Workflow. A new pop up will appear.
Name your workflow. You can set the pin to be randomly generated or to a default one. Here you can also establish how long the PIN should be, and if the user will have to change it on the first usage.
You can also establish a fingerprint policy such as requiring the user to register one at the next use.
Save your workflow to add it to the list of workflows available.
Pre-reg ATKey to Entra ID
Pick the workflow you want to run.
The system will prompt you with three possibilities:
To pre-reg an ATKey for each user
To pre-reg multiple keys to a single account (useful to have both a main and a backup key prepared or for accounts that are shared among multiple people)
To pre-reg all the selected accounts to a single key (useful for users that need access to multiple accounts)
After choosing the modality you will need to select the users you want to register the keys to. The pre-reg tool will show you all the users in your Microsoft environment. you can pick up to 20 users for each cycle.
After the users is time to map them to the ATKeys. Make sure they are connected to the computer. To map them just order them in front of the account they need to be connected with.
Once started the pre-reg process will ask if you want to add any of the key not already registered in ATKey.LCM and will require you to touch or click each key depending on the model when requested to complete the process.
If you are pre-registering ATKey.Card NFC, you will be prompted to remove it and reconnect it with the reader when the credential assignment process begins.
