ATKey.LCM User Guide
ATKey.LCM integrates with Microsoft Entra ID, enabling credential lifecycle management in cloud-first and hybrid deployments.
Who this guide is for: IT Admins setting up ATKey.LCM for their organization for the first time.
IMPORTANT:
In order to use ATKey.LCM the account logged in must be an Entra ID Global Administrator or an Authentication Administrator.
Authentication Administrators also require Cloud Application Administrator or Application Administrator roles to manage ATKey.LCM.
Before You Start
Have these ready before you begin — setup takes about 10 minutes.
| What you need | Notes |
|---|---|
| Microsoft Entra ID tenant | Cloud-first or hybrid deployment |
| Entra ID admin account | See Roles & Permissions for Provisioning for the roles required |
| Referral code | Provided by your Solution Provider. Required — onboarding cannot be completed without it |
| Support email address | Your organization's IT contact for ATKey.LCM |
| ATKey hardware | ATKey.Pro, ATKey.Card NFC, or ATKey.Badge. No keys yet? You can still onboard — see Onboarding Step 2 |
Important Concepts
ATKey.LCM System Architecture
ATKey Serial Number
Each ATKey.Pro and ATKey.Card NFC are trackable through a hexadecimal 8 digits code which is the serial number. Each serial number is unique to one key. The serial number is embedded in the key firmware, as well as printed on the key surface.
Through the serial number it can be traced key production, features, and shipment.
In ATKey.LCM serial numbers and Entra ID users IDs are paired for improved tracking.
ATK.LCM Onboarding
Set up ATKey.LCM for your organization and connect it with Entra ID in less than 10 minutes
Register your account
Visit ATKey.LCM at (https://atkey-lifecycle.authentrend.com/) and use the referral code your partner shared with you.
Use Entra ID and a Microsoft account to login.
Entra ID Global Admin or Authentication Administrator (+ Cloud Application Administrator or Application Administrator) role required to use ATKey.LCM.
You will be prompted to provide a support email and enter any referral code you may have.
ATKey.LCM will require you login into Entra ID and to grant API permission in order to work.
About the Trial you should know:
Onboarding is a one-time setup. Each organization completes it once, and it starts your 60-day free trial.
Don't have a referral code? Contact your Solution Provider, or visit our Free Trial Program to find one.
Don't have ATKeys yet? You can complete onboarding and explore the platform, but ATKey hardware is required to provision users. Our team will follow up with you about getting your first keys.
ATKey.LCM Overview
Dashboard
Upon login you will see the main dashboard.
Here is where you can see the deployment and usage of ATKeys at a glance.
The main metrics shown here are:
Number of active ATKeys
Number of accounts in your Entra ID organization
Number of credentials issued through ATKey.LCM
Number of free ATKeys
Status of the ATKeys registered
User List
The second tab is the full list of the accounts in you Entra ID environment.
For each account you can check to which departments they belong, what their role and which ATKeys are assigned to them.
You can leave notes for future reference.
ATKey Inventory
The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.
Keys details include:
Serial number
Model
Status (free, assigned, lost)
When it was first registered
When was activated
Last use
Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.
ATKey Inventory
The third tab functions as your virtual ATKey inventory, all the keys registered to your organization are here.
Keys details include:
Serial number
Model
Status (free, assigned, lost)
When it was first registered
When was activated
Last use
Here you can change the status of any ATKey that has been registered with the three dots on the right of each ATKey tab.
Pre-Registration Tool
Visit the download tab in the ATKey.LCM interface. Is the fifth from the top on the left side panel.
Download the Admin Credential Pre-reg Tool
Install ATKey.LCM Pre-Reg.
At launch remember to use “Run as an administrator” otherwise the tool would not work.
Due to the Microsoft API limitation:
Admin cannot assign keys to their own account.
Authentication Administrators cannot assign keys to Global Administrators (the reverse is allowed).
Pre-reg Tool Flow for Admin
Add Workflow – Define Organization Key Policy
On opening the Pre-Reg Tool, click on Add Workflow. A new pop up will appear.
Name your workflow. You can set the pin to be randomly generated or to a default one. Here you can also establish how long the PIN should be, and if the user will have to change it on the first usage.
You can also establish a fingerprint policy such as requiring the user to register one at the next use.
Save your workflow to add it to the list of workflows available.
Pre-reg ATKey to Entra ID
Pick the workflow you want to run.
The system will prompt you with three possibilities:
To pre-reg an ATKey for each user
To pre-reg multiple keys to a single account (useful to have both a main and a backup key prepared or for accounts that are shared among multiple people)
To pre-reg all the selected accounts to a single key (useful for users that need access to multiple accounts)
After choosing the modality you will need to select the users you want to register the keys to. The pre-reg tool will show you all the users in your Microsoft environment. you can pick up to 20 users for each cycle.
After the users is time to map them to the ATKeys. Make sure they are connected to the computer. To map them just order them in front of the account they need to be connected with.
Once started the pre-reg process will ask if you want to add any of the key not already registered in ATKey.LCM and will require you to touch or click each key depending on the model when requested to complete the process.
If you are pre-registering ATKey.Card NFC, you will be prompted to remove it and reconnect it with the reader when the credential assignment process begins.
Status and Flow
ATKey and Credentials
ATKey Status
| Status | Meaning | Can change to |
|---|---|---|
| Free | Active key, registered in ATKey.LCM but not assigned to any user | Assigned (assign to user account), Lost, Inactive |
| Assigned | Active key, assigned to one or more user accounts | Free (Revoke ATKey), Lost, Inactive |
| Lost | Active key reported lost by an admin | Assigned or Free (mark as found), Inactive |
| Inactive | Discarded key. Assignments are cleared | Free (reactivate ATKey) |
An assignment creates a relationship between an ATKey and an account (n:n).
Credential Status
| Status | Meaning | Can change to |
|---|---|---|
| Active | Credential is registered and usable | Revoked (revoke credential) |
| Revoked | Credential is no longer usable | — |
Credential status is separate from ATKey status. An ATKey remains assigned to its user even after its credentials are revoked
Actions
| Tab | Action | Details |
|---|---|---|
| Account Tab | Withdraw ATKey (Assigned → Free) | Available when ATKey status is Assigned |
| ATKey Tab | Mark ATKey as lost (→ Lost) |
Available when ATKey status is Free or Assigned User will be asked whether to revoke the credentials above |
| ATKey Tab | Mark ATKey as found (→ Assigned/Free) |
Available when ATKey status is Lost Status change: - If key has assignment, status return to assigned - If key has no assignment, status return to free |
| ATKey Tab | Discard ATKey (→ Inactive) |
Available when ATKey status is Free, Assigned, or Lost The credentials above will be revoked |
| ATKey Tab | Reactivated ATKey (→ Free) | Available when ATKey status is Inactive |
Trial & License
Your 60-day free trial
What counts as a licensed user
A user counts toward your license once they have been assigned an ATKey. In ATKey.LCM this count is shown as ATKey Users.
Clearing a user's ATKey assignment does not release the seat. The seat is released only when the user is removed from Entra ID and ATKey.LCM completes its next sync.
When your trial ends, upload a license key on the Subscription page to continue managing ATKeys. Contact your Solution Provider to obtain one.
The license you upload must cover at least your current ATKey Users count. If it covers fewer users, the upload will be rejected.
Activating your license
Onboarding starts a 60-day free trial with no limit on the number of users. You can sync your full Entra ID user list and provision keys across your organization during the trial.
License status affects managing keys in ATKey.LCM — adding users, assigning keys, and syncing with Entra ID. It does not affect end users signing in with the ATKeys they already have. Daily authentication continues to work normally.
End users are not affected
Need Help?
| Question about | Contact |
|---|---|
| Referral code, licenses, ordering ATKeys | Your Solution Provider |
| Product support | customer.support@authentrend.com |
| Finding a Solution Provider | Free Trial Program |
