Fast User Switching with Windows Authclient
  • 07 Jun 2023
  • 4 Minutes to read
  • Dark
    Light

Fast User Switching with Windows Authclient

  • Dark
    Light

Article Summary

Fast User Switching with the RapidIdentity Windows Authentication Client

When enabled, Fast User Switching allows multiple users to share a single windows device, using their own unique Windows login credentials, and easily switch between them without logging an active user session out or closing any windows.

Fast User Switching makes it easy for Windows users to share a single device but, might not be appropriate for users with dedicated devices. As such, the RapidIdentity Windows Authentication Client now tolerates and respects both the Fast User Switching enabled and disabled states which can be set by adminstrators using the Hide entry points for Fast User Switching policy setting.

Hide entry points for Fast User Switching

The Hide entry points for Fast User Switching policy setting allows administrators to hide the Switch User interface in the Logon UI, the Start menu and the Task Manager.

When this policy setting is enabled, the Switch User interface is hidden from the user who is attempting to log on or is logged on to the computer that has this policy applied.

The locations that Switch User interface appear are in the Logon UI, the Start menu and the Task Manager.

If the policy is disabled or not configured, Switch User interface is accessible to the user in the three locations.

Note:

To change the Windows Fast User Switching settings, you must have the ability to edit the Registry/GPO settings for the Windows machine.

GPO Policies/Registry Settings to update:

  1. Hide entry points for Fast User Switching: If this policy is enabled, the Switch User interface is hidden from the user attempting to log on or the lock screen for a logged-in user.

    Administrative users can choose one of the following two ways to adjust this setting :

    1. Using the GPO: in gpedit.msc navigate to Local Group Policy>Computer Configuration>Administrative Templates>System>Logon and set Hide entry points for Fast User Switching to Enabled or Disabled. Enabling this policy will disable Fast User Switching.

    2. Using the Registry Editor: navigate to
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] and set HideFastUserSwitching equal to dword:00000001

  2. Don't display last signed-in: If this policy is enabled, the last logged-in user name is hidden from the lock screen.

    Administrative users can choose one of the following two ways to adjust this setting:

    1. Using GPO: in gpedit.msc navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options and set Interactive Logon:Don't display last signed-in to Enabled or Disabled

    2. Using the Registry Editor: navigate to [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] and set dontdisplaylastusername equal to dword:00000001

Fast User Switching behavior in the Windows Authclient

When FUS is Enabled:

If an Admin enables this setting and users lock their machines, the switching user option from logged-in window is disabled, and any other user attempting to log in through the Windows Authclient login process will be given an error message by Windows, which means only the locked user can unlock the machine and the session remains active.

Step 1 : Admin/ User Enable FUS.
17a508c0-c5f8-4a13-b611-c768b41c65e0.png

Step 2 : Sign out from the machine.
Step 3 : User logs in using RI Client with any Authentication method (Example shown here with Password).
9353e673-f760-4876-8c1e-7440c0dad35d.png

5f07f29a-7838-4eba-92aa-381b7fac3dd1.png

Step 4 : Once user logged in using WAC user will be redirected to RI Profile. User can work and locks the machine.
Step 5 : User will not see the switch user option on the logged-in window.

a7bc2976-e706-48f9-b178-b82d61628670.png

Step 6 : Other WAC user tries to login using any authentication method.
52829cc0-e657-4cdf-8a5a-836662e05ee3.png

a2a389f0-6100-4c75-ba15-adf666a51a68.png

When other user tries to log in, Windows will display error message.

When FUS is Disabled:

When FUS is disabled and the machine is locked, any user can log in via with Windows Authclient. They also will be prompted with the Switch User option on Log in Screen.
908b579e-8c05-40c9-a9bc-22752a26b831.png

Step 1 : Disable FUS
c8b724dd-919c-484e-ba4b-02b2c5a13a90.png

Step 2 : Login with a WAC user and lock the session.
Step 3 : Login with any other WAC user using any authentication method (Password, Duo, SMS etc).
52829cc0-e657-4cdf-8a5a-836662e05ee3 1.png

Step 4 : User successfully logs in.
Step 5 : User locks the machine. Now any user can switch easily to their account by clicking on Switch user.
7c34d31c-54b8-4d5a-9ff5-7cf753099c18.png

Note:

All users who locked their machine and return to their session at a later time will have the session maintained by Windows.

  • When dontdisplaylastusername is enabled: This setting only affects the Windows Logged-in screen when FUS is enabled.

    • FUS and dontdisplaylastusername is enabled: When both of these settings are enabled, users can not see the last logged-in user name on the Log-on Screen.
      54a2f1b5-5bff-4570-a9ac-c699ead497e7.png

    6616464f-a075-450c-b488-862f9bdf70fc.png

    • FUS is enabled and dontdisplaylastusername is disabled: When FUS is enabled and dontdisplaylastusername is disabled then user can see the last logged-in user name (Domainname\username) on the Log-on Screen.

    7fb0ea27-a93f-44bc-a58f-865eb5d7db64.png

316acf69-2bc6-481c-b5dc-6ccad9e282be.png

Note:

Do not uninstall or update the Windows Authentication Client if any user has a locked session on the device. This will cause issues the next time the Windows Authentication Client installer is run.

d7162e33-4226-4982-8c13-bccb4441167e.png


Was this article helpful?