Overview
Administrators configure Identity Guardian and set up profiles for shared or personally assigned devices through Managed Configurations.
Each user is required to complete a one-time enrollment process before authentication and sign in. For users opting to use facial biometrics (if configured by the administrator), customizable Terms and Conditions must be reviewed and accepted. Once enrollment is complete, users can sign in and out of the device as needed.
The enrollment workflow can be further streamlined using the Identity Guardian zCreator companion app, offering:
- Barcode printing and sharing: Effortlessly print, preview, and resize barcodes. This is seamlessly integrated with the enrollment process, supporting both Zebra and Canon printers, and also allows barcodes to be shared.
- NFC card writing: Write user data to NFC cards when NFC data is saved during enrollment.
This section also discusses additional features available as part of the authentication process, such as:
Identity Guardian expands support to Zebra wearable computers, delivering an optimized, compact interface for streamlined multi-factor authentication on devices such as WS301 and WS501.
User Enrollment
The required on-device enrollment procedure depends on the device access method:
Zebra DNA Cloud-Based User Management
For environments utilizing Zebra DNA Cloud-based user authentication, on-device enrollment is bypassed entirely. Administrators configure Identity Guardian users centrally within the Zebra DNA Cloud console beforehand. To enable this, the administrator applies the following Shared Device Authentication settings (with remaining options selected as needed) to the devices:
- Comparison Source: CLOUD
- Primary Authentication Factor: CLOUD_PASSCODE
- Fallback Authentication Method: ADMIN BYPASS PASSCODE
Once configured, users access devices simply by entering their designated cloud passcode, which Identity Guardian verifies in real-time against Zebra DNA.
Shared Device
To sign in or authenticate on a shared device, users must first complete enrollment with Identity Guardian. There are three methods for enrolling users on shared devices:
- Standard Enrollment - Users enroll on a designated device using the Enrollment profile set up by their administrator. Afterward, they can authenticate on the shared device where the Authentication profile has been deployed.
- Self-Enrollment - Both enrollment and authentication are performed directly on the shared device, facilitated by the Authentication profile deployed by the administrator.
Once enrollment is complete, the user are provided the option to print or share the barcode if the zCreator app is installed. This app is mandatory for Self-Enrollment but optional for Standard Enrollment, since Standard Enrollment inherently includes the ability to save barcodes.
For enhanced security, configure Automatic Barcode/NFC Expiration. Once an enrollment expires for barcode or NFC card authentication modes, the system automatically restricts device access and prompts the user to re-enroll, ensuring credentials remain valid and up to date.
Standard Enrollment
After administrators deploy specific settings through a standard enrollment profile to a device designated for user enrollment, follow these steps to enroll users (steps may vary depending on the options configured):
In Identity Guardian, tap Start.

(Optional) This is a 6 digit PIN set by the administrator. Tap Continue.

Setup ID and passcode:
- Enter ID or email (Maximum of 60 characters. Note: This is case-sensitive — the string entered must exactly match that from the identity provider. Discrepancies may lead to authentication issues or failure if using the Auto-Fill SSO Login feature.)
- (Optional) Select the appropriate user role (options vary based on your administrator setup).
- (Optional) Select the enrollment expiration date, applicable for assigning temporary users.
- Create a passcode based on the requirements set by the administrator.
- Re-enter the passcode

(Optional) Capture facial biometrics. If opting out (as determined by the administrator's configuration), tap Skip and proceed to step 7 below. Otherwise, tap Add and follow the subsequent steps.

Read the Terms & Conditions. Tap Confirm to accept.

Position your face within the device screen for the photo capture. Capture 1 to 3 facial photos that may vary based on the individual's look, for example, with eyeglasses, hat, etc. Confirm the photo capture(s). Tap Add to capture additional photos. Tap Next when done.

Choose one of the following steps based on your administrator's data storage configuration:
- NFC: Select one of the following:
- Save: Saves the NFC data to the device for 24 hours. Within this timeframe, the user must use zCreator to write their data to an NFC card. At this point, the NFC enrollment process is complete. Do not proceed to the next step.
- Write to NFC: To write the data to an NFC card, tap Write to NFC. When prompted to write to the NFC card through zCreator, touch the NFC card to the device until the write is complete. Once the write is complete and Identity Guardian is displayed, tap Continue to finish the enrollment process. At this point, the NFC enrollment process is complete. Do not proceed to the next step.
Note: This option does not save the NFC data to the device.



- Barcode: The user barcode is generated. Tap Next, then proceed to step 8.

- NFC: Select one of the following:
To complete the enrollment process for barcodes, follow one of the options below based on the configurations set by your administrator:
No Barcode: If barcode printing is not required, tap Save to complete the enrollment process.

Save the Barcode: If the "Allow opening barcode during enrollment" option in Enrollment Configuration is disabled, barcode printing or sharing is not permitted during enrollment. Tap Save to save the barcode as a PDF file. It is stored in the
/enterprise/usr/profilesfolder on the device and can be accessed later via zCreator. Tap Continue to finalize the enrollment process.

Print or Share the Barcode: If the "Allow opening barcode during enrollment" option in Enrollment Configuration is enabled, both the Print and Share buttons are visible.
Printing or Sharing Barcode: Tap Print to launch the zCreator app, where the barcode displays on the preview screen. For detailed instructions on printing or sharing, see Print & Share Barcode. After printing or sharing, tap the back button in zCreator to return to Identity Guardian, then tap Continue to complete enrollment.
Notes:This option does not save the barcode to the device.
If the user taps the back button in zCreator without printing the barcode, the Identity Guardian screen returns with the Continue button visible. However, the user loses the opportunity to print their barcode, and the previous enrollment steps cannot be revisited.



Saving the Barcode: Tap Save to save the barcode as a PDF file. It is stored in the
/enterprise/usr/profilesfolder on the device and can be accessed later via zCreator.

To retrieve the saved barcode for printing or sharing after enrollment, use the zCreator app. Open zCreator at any time to view, print or share the stored barcode.
After completing enrollment, the user can then sign in to the shared device where the administrator has deployed the authentication profile.
Note: If a user is in the middle of the standard enrollment process and the Admin deploys the Identity Guardian profile for authentication, the user may encounter the lock screen shown below and be unable to sign in. To resolve this, the user should reboot the device.
Self-Enrollment
Users can self-enroll directly from the lock screen on shared devices, allowing for immediate enrollment and authentication on the same device. This streamlines the process by eliminating the need for separate Enrollment and Authentication profiles. Administrators activate this feature through specific settings through a Self-Enrollment Profile deployed to the devices.
Usage
On the lock screen, tap the menu icon in the top right corner and select Enroll User.

Optional: If Keyguard and Corporate PIN are enabled, the user is prompted to enter the corporate PIN. This is a 6 digit PIN set by the administrator. Tap Continue.

Enter the user's SSO login credentials.

Provide the requested information for enrollment, then tap Next:
- Employee ID or Email - This is populated based on the user ID entered in the SSO login screen. Maximum of 60 characters.
- Role - This is populated based on the user ID entered and their role mapped in their SSO provider.
- Create Passcode - Enter a passcode to create.
- Re-enter Passcode - Enter the same passcode again.


Tap Add.

Tap Confirm to accept the Terms & Conditions, then perform a facial capture. Tap Next.

Choose one of the following steps based on your administrator's data storage configuration:
- NFC: Tap one of the following buttons:
- Exit: Exits the enrollment process.
- Write to NFC - Writes the data to an NFC card. When zCreator launches, it prompts the user to touch the NFC card to the device until the write is complete. Once the write is complete and Identity Guardian is displayed, tap Continue to finish the enrollment process. At this point, the NFC enrollment process is complete. Do not proceed to the next step.
Note: This option does not save the NFC data to the device.



- Barcode: The user barcode is generated. Tap Next, then proceed to step 7.

- NFC: Tap one of the following buttons:
Print or Share Barcode: Tap Print. This opens zCreator app in the preview screen to allow for immediate printing or sharing of the barcode. Proceed to the Print & Share Barcode section for the available options.
Note: The barcode is not automatically saved. To save it manually, see Print & Share Barcde.
Tap the back button to return to the enrollment screen.

Tap Continue to finalize the enrollment process.
To print or share barcode (if saved), launch the zCreator app at any time.
After completing enrollment, the user can then sign in to the shared device.
Note: To exit self-enrollment in the middle of the process, the user must repeatedly tap the back button until the Identity Guardian lock screen is displayed.
|
Step 6: Provision Credentials Finalize credential creation according the data storage configured by your admin. |
|
|
Step 6a: Barcode Option View the generated user barcode and tap Next. In the next screen, tap |
|
|
Step 6b: NFC Option Tap Write to NFC, hold the NFC card against the device until the write completes. When successful, a confirmation message appears. |
|
**User Enrollment via Web Browser (on host PC):** **NOTE:** Enrollment progress is not saved automatically. Closing the web browser prior to completion requires restarting the workflow from the enrollment link.
| Step & Instructions |
|---|
|
Step 1: Initiate Enrollment Open the enrollment link provided in the invitation email. Enter the username specified in the email and click Get One Time PIN.
|
|
Step 2: Authenticate with PIN Retrieve the one-time PIN sent via email and enter it to authenticate. If the email is delayed or not received, wait for the on-screen countdown timer to expire before requesting a resend. Note: Five consecutive failed attempts block enrollment completely.
|
|
Step 3: Create passcode Create and confirm a new passcode adhering configured passcode rules, then click Next.
|
|
Step 4: Biometrics Consent Review and accept the biometric consent terms if facial biometrics are required. If not, skip to step 7.
|
|
Step 5: Facial Capture Instructions Review the facial capture guidelines, then click Continue.
|
|
Step 6: Capture Facial Biometrics The screen displays the required image count. Click Add to begin capturing each image, or click Skip if facial opt-out is permitted by your administrator. ![]() Center your face within the viewfinder frame during image capture. ![]() As each image is captured, the screen displays the remaining required count. An image can be removed and retaken. Once all required images are captured, click Done.
|
|
Step 7: Complete Enrollment The enrollment process is complete. The system generates and emails the barcode or NFC credential data file to the registered email address.
|
Update Existing Enrollment Data
** A Shared-Device User possessing an active barcode or NFC card can refresh passcodes or facial biometric images independently without contacting an administrator.| Instructions | Screen Capture | ||||||
|---|---|---|---|---|---|---|---|
|
Step 1: Authentication On the lock screen, tap the menu icon in the top right corner and select Enroll User. |
|
||||||
|
Step 2: Request Update Tap Update Existing Barcode or Update Existing NFC based on the enrollment method. Authenticate against the existing profile when prompted. |
OR
|
||||||
|
|||||||
Replace a Lost Barcode or NFC Card
** When physical credentials are lost (barcode or NFC card), re-enrollment requires Administrator authorization before device access can be restored.| Role | Instructions | Screen Capture / UI |
|---|---|---|
| End-User | On the Identity Guardian lock screen, tap the menu icon in the top right corner and select Enroll User. |
![]() |
| End-User | Enter the user name. Based on the enrollment method, tap either Replace Lost Barcode or Replace Lost NFC. |
OR ![]() |
| Administrator | The administrator reviews the pending request under User Request on the Device Users page in Zebra DNA Cloud and approves or denies the request.![]() |
|
| End-User | Request Approved: If the request is approved, the user receives an approval email containing a re-enrollment One-Time PIN. Open Enroll User on the device to re-enroll. Follow the User Enrollment steps above. Request Denied: If the request is denied, the user receives an email indicating the denied request. No further action can be taken on the device. |
|
Automatic Barcode/NFC Expiration
Automatic Barcode/NFC Expiration allows administrators to enforce enrollment expiration periods to maintain credential security for Shared Devices. Once an enrollment credential (barcode or NFC card) reaches its expiration date, the device immediately blocks access and launches a secure re-enrollment workflow, ensuring only authorized personnel retain active credentials.
Admin Setup
- Configure EMM Managed Configurations:
- Under Shared Device Authentication, enable Automatic Barcode Expiration by setting it to
true. When enabled, the system blocks expired barcodes and triggers the re-enrollment workflow. When disabled, expiration timestamps are ignored, permitting device access with an expired barcode. - Under Enrollment Configuration locate Secure Re-Enrollment and set it to
trueto allow users to initiate self-service re-enrollment, orfalseto mandate administrator intervention.
- Under Shared Device Authentication, enable Automatic Barcode Expiration by setting it to
- Registered Email Address: The user account must have a valid email address configured in the ZDNA console to complete re-enrollment via One-Time PIN.
- Barcode Generation Utility: The zCreator application must be installed on the device to generate and print new enrollment barcodes following successful re-enrollment.
Limitations:
- Authentication Requirements for Re-enrollment: Secure re-enrollment requires verification through Single Sign-On (SSO) or a One-Time PIN sent to an accessible, registered email address. Users without SSO or a registered email cannot self-service and must contact an administrator.
- Unsupported Authentication Methods: Secure self-service re-enrollment is not supported for Cloud Passcode or Pure SSO authentication modes. If an enrollment expires under these modes, device access remains blocked until an administrator intervenes.
Usage
The expiration workflow functions according to the primary authentication method configured on the device.
Scenario A: Barcode or NFC Authentication:
- Login Attempt: The user scans their expired barcode or taps their expired NFC credential.
- Expiration Notification: An alert displays indicating that the enrollment has expired.
- If Secure Re-enrollment is Enabled: The user selects Re-enroll.

- If Secure Re-enrollment is Disabled: The user can only select Cancel and must contact an administrator.

- If Secure Re-enrollment is Enabled: The user selects Re-enroll.
- Identity Verification: After selecting Re-enroll, the user must complete identity verification before creating new credentials:
- SSO Configured: The user logs in with SSO credentials. Upon successful authentication, the system opens the self-enrollment screen.
- SSO Not Configured (One-Time PIN Flow):
- A 6-digit One-Time PIN is sent to the registered email address.
- The user submits the One-Time PIN on the device. Following successful verification, the system proceeds to the self-enrollment screen.
- Self-Enrollment: The user follows on-screen prompts to establish a new passcode, facial biometric scan, or both.
- Credential Generation: The user prints or writes the new credential to an NFC card using the zCreator application. Selecting Print or Write NFC transmits the updated enrollment record to the ZDNA console, visible under Device Users.
Scenario B: Cloud Passcode Authentication:
- Login Attempt: The user enters the Cloud Passcode on the device.
- Verification: The system validates the passcode against the ZDNA portal.
- Expiration Notification: If the passcode is valid but the enrollment has lapsed, a dialog notifies the user that the enrollment has expired. Because self-service re-enrollment is unsupported for Cloud Passcode authentication, the prompt only displays a Cancel button, requiring administrator assistance.
Scenario C: SSO-Only Authentication:
- Login Attempt: The user authenticates strictly with SSO credentials.
- Verification: The system authenticates against the identity provider and verifies user status against the ZDNA portal.
- Expiration Notification: If credentials pass but enrollment has expired, a dialog indicates that the enrollment has expired. Because self-service re-enrollment is unsupported for SSO-only mode, the interface presents only a Cancel option, requiring administrator intervention.
Error Handling and Edge Cases:
The table below outlines system behavior, on-screen notifications, and resolution steps for potential failure scenarios during re-enrollment:
| Scenario | System Message | Required Action |
|---|---|---|
| Email Not Registered | "Email is not registered. Please contact administrator to complete re-enrollment." | The user must contact an administrator to associate a valid email address with the account in the ZDNA console. |
| Invalid One-Time PIN Entry | Displays remaining attempts (up to 3 total attempts). | Enter the correct 6-digit One-Time PIN received via email. |
| Exceeded One-Time PIN Attempts | "Maximum One-Time PIN verification attempts reached. Please request a new One-Time PIN." | Re-scan the expired barcode to generate a new One-Time PIN and restart verification. |
| User Profile Not Found | "Device user not found. Please contact admin for re-enrollment." | Contact an administrator to confirm the user profile exists and is active in the ZDNA console. |
Personally Assigned Device
Before users can sign in or authenticate on a personally assigned device, they must first register with Identity Guardian. Administrators create and deploy the personally assigned profile, then launch Identity Guardian on the device to initiate the enrollment process. The options available to users during the on-device enrollment process may vary based on the Enrollment Configurations set by the administrator.For more details on how to apply the settings, see the EMM Setup section.
After the enrollment process, the user is immediately presented with the authentication screen.
Warning: If a user suspends and resumes the device in the middle of enrollment, the enrollment process restarts from the beginning.
To enroll users on personally assigned devices:
- Open Identity Guardian.
- Tap Start.

- Enter corporate PIN. This is a 6 digit PIN set by the administrator. Tap Continue.

- Select one of the following based on whether Keyguard is enabled:
- Keyguard Enabled:
- Enter ID or email (maximum of 60 characters).
- (Optional) Select the appropriate user role (options vary based on setup by your adminstrator)
- Tap Next.

- Keyguard Disabled:
- Enter ID or email (maximum of 60 characters).
- (Optional) Select the appropriate user role (options vary based on setup by your adminstrator).
- Create a passcode, which can contain up to 6 alphanumeric characters.
- Re-enter the passcode.
- Tap Next.

- Keyguard Enabled:
- (Optional) Capture facial biometrics. If opting out (as determined by the administrator's configuration), tap Skip and proceed to step 7 below. Otherwise, tap Add and follow the subsequent steps.

- Read the Terms & Conditions. Tap Confirm to accept.

- To add a facial photo, tap Add. Position your face within the device screen for the photo capture. Capture 1 to 3 facial photos that may vary based on the individual's look, for example, with eyeglasses, hat, etc. Confirm the photo capture(s). Tap Add to capture additional photos. Tap Next when done.

- Tap Save to save the profile.

- Tap Continue. The profile creation is complete.

Edit Profile
To edit a profile on a personally assigned device:
- Open Zebra Biometric app.
- Proceed with one of the following options based on the administrative configuration:
- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."

- Facial biometric authentication: Scan the user's face. This applies if the Primary Authentication Factor is set to "FACE."
- Passcode entry: Enter the user-defined passcode. This applies if the Primary Authentication Factor is set to "PASSCODE."

- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."
- Select the item to edit:
- ID & Passcode
- Face Recognition

- If ID & Passcode is selected, make the appropriate edits and tap Save:
- Role - select the desired role
- Passcode - enter the current passcode and the new passcode

- If Face Recognition is selected, delete the existing facial photo and replace it by capturing a new photo.

Delete Profile
To delete a user profile on a personally assigned device:
- Open Zebra Biometric app.
- Proceed with one of the following options based on the administrative configuration:
- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."

- Facial biometric authentication: Scan the user's face. This applies if the Primary Authentication Factor is set to "FACE."
- Passcode entry: Enter the user-defined passcode. This applies if the Primary Authentication Factor is set to "PASSCODE."

- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."
- Tap on the menu icon at the top right and select Delete Profile.

After the user profile is deleted, the enrollment screen appears for a user to re-enroll to the device and authenticate the user.
Print & Share Barcode (zCreator)
Unique, encrypted QR Codes serve as a secure authentication method for signing into Shared Devices. These barcodes are generated based on either facial recognition or a passcode.
Using the zCreator app, users can print or share their QR Codes during the Standard Enrollment (if configured by the administrator) or Self-Enrollment process. However, the ability to manage, print, or share the QR Code after enrollment differs significantly between the two methods:
- Standard Enrollment
- File Storage: The QR code is automatically saved as a .PDF file in the
/enterprise/usr/profilesfolder during the enrollment process. - zCreator App Role: The zCreator app is optional, required only if users need to access, print, or share the saved barcode file.
- Post-Enrollment Access: Because the .PDF is saved locally, users can access, print, or share their QR code at any time after enrollment.
- File Storage: The QR code is automatically saved as a .PDF file in the
- Self-Enrollment
- File Storage: The QR Code is not automatically saved to the device.
- zCreator App Role: The zCreator app is mandatory to print or share the barcode, and this action must take place during the active enrollment flow.
- Post-Enrollment Access: Self-Enrollment QR Codes cannot be reprinted, recovered, or shared using the zCreator app once enrollment is finalized. Because the barcode is never saved to the local file system, users do not have access to it after completing enrollment. If the barcode is lost, the user must undergo the self-enrollment process again to generate a new QR Code
Guidelines & Behavior:
- Barcode Orientation: When previewing barcodes, the Preview screen displays the barcode in portrait mode.
- Character Display Limits: A maximum of 35 characters are displayed for the user name on the preview screen, even if the actual name is longer.
Requirements and Options
Before barcodes can be printed or shared, administrators must install and configure the zCreator app. Refer to the Standard Enrollment or Self-Enrollment setup procedures for guidance.
Instructions to adjust zCreator settings within the app, such as QR Code size, IP address, or MAC address, are provided in Configure zCreator.
Printing Barcodes (see Supported Printers):
- Network or Bluetooth Printers: Ensure the device and printer are connected to the same network.
- Bluetooth Printers: Ensure the device and printer are paired prior to printing.
- Network printers (WiFi or Ethernet)
- Canon Printers:
- Ensure the device and printer are connected to the same network.
- Use the Share To feature to select the Canon Print app and follow the prompts to print.
- Zebra Printers:
- Ensure the device and printer are connected to the same network.
- NFC Tap & Pair: Uses NFC to detect and connect with a printer:
- Enable NFC on both the device and printer.
- Tap the device with the printer's NFC tag. It initiates the device to automatically discover the communication method with the printer in this sequence: Ethernet, WiFi, Bluetooth. This process may take up to 30 seconds to complete.
- If using Bluetooth, pair the device and printer beforehand. Once detected, the Preview screen appears allowing the user to print.
Sharing Barcodes: The barcode is shared as file shared_image.png.
- Gmail: Attaches the barcode to an email. Ensure a Gmail account is pre-configured on the device. Select Gmail from the Share app chooser screen and compose the email with the attached barcode.
- Bluetooth File Transfer: Sends the barcode to another device (non-printer) via Bluetooth.
- NFC Tap & Pair: Enable NFC on both the device and printer. Tap the device near the printer's NFC tag to initiate the discovery process. The device sequentially searches for nearby printers using Ethernet, WiFi, or Bluetooth. This process may take up to 30 seconds to complete. This feature is particularly useful if the printer's IP or MAC address is not known.
During Enrollment
At the end of the enrollment process (either Standard or Self-Enrollment), tapping the Print button launches zCreator in the Preview screen. From the dropdown menu, users can select their printing or sharing preference based on the configuration set by their administrator:
Network ZPL Printer:
Tap Printer ZPL Network to initiate printing. If successful, a confirmation message appears indicating that the print job was completed successfully.

Bluetooth ZPL Printer:
Tap Printer ZPL Bluetooth to initiate printing. If the device and printer are not already paired, the user is prompted to pair them. Once paired, a confirmation message appears upon successful printing.

Share To: Shares the barcode as
shared_image.png. Tap Share To.
Select one of the following options:
- Canon Printer: Tap the Canon Print app and follow the prompts. If the app is not visible, scroll to locate it. Ensure to follow the Canon Printer Calibration guideline.

- Other printers or devices:
- Print - Tap the option Save as PDF, enter a file name, and tap Save. The .PDF file is saved in the Downloads folder.
- Bluetooth - Shares files with another device (non-printer) via Bluetooth.
- Gmail - Ensure a Gmail account is added beforehand. Once added, select the Gmail account to open the compose email screen with the barcode attached as a .PNG file.

- NFC Tap & Pair: Ensure that NFC is enabled on both the device and printer. If connecting via Bluetooth, the printer and device must be paired. To use this feature:
- Canon Printer: Tap the Canon Print app and follow the prompts. If the app is not visible, scroll to locate it. Ensure to follow the Canon Printer Calibration guideline.
- Tap the device near the printer's NFC tag.
- The NFC Tap & Pair screen appears and initiates the discovery process to locate nearby printers. Printers are discovered in the following order: Ethernet, WiFi, and Bluetooth. This process may take up to 30 seconds.
- Once the printer is found, the Preview screen displays, showing the appropriate connection method (e.g. Bluetooth ZPL Printer).
- Follow the instructions based on the connection method:
- Ethernet or WiFi: Follow the Network ZPL Printer instructions above.
- Bluetooth: Follow the Bluetooth ZPL Printer instructions above.


Example of NFC Tap & Pair with a Bluetooth printer
After Enrollment
Barcodes created during standard enrollment are saved in zCreator. To access them after the enrollment process is complete:
- Open the zCreator app.
- In the main screen, select the desired barcode file to open.
- The barcode appears in the Preview screen. Choose to print or share the barcode using the methods outlined in the During Enrollment section above.
![]() |
![]() |
|
| Select the barcode file to open in Preview. | ||
Guidelines and Behavior
This section provides guidelines and expected behaviors for printing and sharing barcodes:
Printer Calibration and Media:
- Network Connectivity: Ensure that the supported printer and the Zebra device are connected to the same network.
- Canon Printer Calibration: When printing with a Canon printer, the zCreator app sends the QR Code for printing. Proper calibration and adjustment of the Canon printer settings are essential to ensure the barcode is printed correctly. Failure to calibrate or configure the settings properly may result in issues such as unscannable or cropped QR Codes.
- Recommended Media: Use Zebra-supplied roll paper that matches your printer model (mobile, desktop, or tabletop). For example, mobile printers should use Zebra-provided mobile printer paper rolls for optimal results.
QR Code Printing:
- Prevent Cropped QR Codes on Labels: Use the Zebra Printer Setup Utility App to specify the width and height of the label, ensuring it prints properly without being cropped on labels.
- Preview Screen Character Limitations:
- When tapping the Print button in Identity Guardian during user enrollment, the Preview screen in zCreator displays the user name with a maximum length of characters.
- When opening a .PDF from the main screen of the zCreator app, the Preview screen limits the displayed user name to 35 characters, even if the actual user name exceeds this length.
- Preview Screen Barcode Alignment:
- During enrollment, barcodes displayed in the Preview screen are left-aligned when the Print button is tapped.
- When opening the barcode .PDF file from zCreator after enrollment, the barcode appears center-aligned in the Preview screen.


Barcode left-aligned. Barcode center-aligned.
- QR Code Size Variation for Zebra Printers: The actual size of the QR code may vary slightly from the specified dimensions, with a possible deviation of 0.1 cm.
- QR Codes Can be Scanned Directly from the Preview Screen: A QR Code displayed on a device can be scanned by another device straight from the Preview screen.
Connectivity and Technical Behavior:
- Bluetooth Pairing for Printing: If the mobile device is not paired with the printer during the first Bluetooth print request, users be prompted to pair with the device. The pairing request must be accepted to proceed.
Note: On some printer models, printing may not begin immediately after pairing. In such cases, users may need to re-initiate the print request. - Printing from Multiple Bluetooth Printers: Simultaneous printing from multiple devices is not supported over Bluetooth. If print jobs need to be performed via Bluetooth on multiple printers, Zebra recommends to introduce a delay of at least 30 seconds after the completion of the first device's print job before initiating the print job on the second device.
- NFC Tap & Pair:
- Workflow: During the NFC Tap & Pair process, the system prioritizes connection types in the following order:
- Ethernet Printer: The system first searches for an Ethernet printer.
- Wi-Fi Printer: If an Ethernet printer is not detected, it attempts to connect to a Wi-Fi printer.
- Bluetooth Printer: If both Ethernet and Wi-Fi connections fail, the system switches to Bluetooth. Even if certain settings, like access to printer configurations, are disabled by the administrator, printing can still proceed based on printer detection via NFC.
- Bluetooth Connection: When connecting to a Bluetooth printer using Tap & Pair, users may encounter a socket connection error. If this occurs, retry the Tap & Pair process. In most cases, it should succeed on the second attempt. If the problem persists, multiple retries may be necessary.
- Wi-Fi Connection: If the Wi-Fi connection fails, a connection error may occur. Ensure that both the printer and mobile device are on the same Wi-Fi network, then retry the Tap & Pair process to establish the connection.
Launch Apps to Share
The self-enrollment workflow is optimized to ensure seamless, uninterrupted barcode sharing with Microsoft SSO-enabled applications such as Microsoft Teams and Outlook. This feature resolves a common challenge where sharing intents were lost if a user was not already logged into the receiving application, forcing them to authenticate, manually return to the zCreator application, and restart the sharing process.
To deliver a smoother experience, a dedicated screen is introduced during initial setup:
- Pre-Select & Authenticate: Users pre-select their preferred sharing application, which automatically launches to complete Single Sign-On (SSO) and establish an active session before the barcode is generated.
- Automatic Sharing: When the user is ready to share the enrollment barcode, the target application is already logged in and running in the background, allowing the barcode to transmit instantly without interruption.
Note: This feature is currently limited to Microsoft Teams and Outlook applications.
Prerequisites
- SSO configuration must be set to use Microsoft Entra IDP.
- The Microsoft Authenticator (Broker App) must be configured for shared device mode.
Admin Setup
Configure the following Managed Configurations:
- In Enrollment Configuration:
- Enrollment Storage Method: BARCODE
- In Lock Screen Configuration:
- Secure Self Enrollment: true
- User Verification: SSO
- Apps Allowed on Lock Screen: Click Add Application Details and enter the following Package Name and Activity Name as needed:
Application Package Name Activity Name Microsoft Outlook com.microsoft.office.outlookProvide the specific activity name, or enter *to allow all activities from the app to run on top of the Identity Guardian lock screen.Microsoft Teams com.microsoft.teamsProvide the specific activity name, or enter *to allow all activities from the app to run on top of the Identity Guardian lock screen.Permission Controller (for use of Microsoft Teams) com.google.android.permissioncontrollercom.android.permissioncontroller.permission.ui.GrantPermissionsActivity - Authorize the barcode sharing application: Click Add Application Details and enter the following Package Name and Activity Name as needed:
Application Package Name Activity Name Microsoft Outlook com.microsoft.office.outlookcom.acompli.acompli.CentralActivityMicrosoft Teams com.microsoft.teamscom.microsoft.teams.mobile.views.activities.MainActivity
- Save and deploy the changes.
Usage
The following steps outline the self-enrollment and barcode sharing experience for end-users on the device.
- Initiate Self-Enrollment: On the device lock screen, tap the menu in the upper-right corner and select Enroll User to begin the process.

- SSO Authentication: The device redirects to the Microsoft Identity Provider (IDP) login page. Enter the required enterprise credentials to authenticate.

- Application Launch (Active Session Setup): After successful authentication, a screen prompts to "Choose an application to share the barcode". Select an authorized application (Microsoft Teams or Microsoft Outlook). The system automatically signs the user in using the active Single Sign-On (SSO) session.
Note: Tapping Skip to continue bypasses this step, but requires a manual login and manual barcode sharing later within Teams or Outlook.

- Complete Enrollment & Share Barcode: Follow the remaining on-screen instructions to complete the enrollment. Once finished, tap Print to launch the zCreator application and display the unique enrollment QR code. Tap Share To to seamlessly transmit the enrollment barcode via the pre-authenticated Teams or Outlook application.
Error Handling and Edge Cases
The following scenarios describe the system behavior and recovery steps under specific device or network conditions.
- No Network Connectivity: If the device lacks an active internet connection when selecting a sharing application, the screen displays: “Please check your internet connectivity.”
To resolve: Establish a stable network connection to proceed, or tap Skip to continue to proceed with the enrollment process without sharing the barcode via Microsoft Teams or Outlook at the end of enrollment. - Application Launch Timeout: The enrollment process automatically cancels and signs the user out of the current session, returning the device to the lock screen, if the selected application fails to launch and become interactive within 30 seconds. This timeout typically occurs due to:
- Low network connectivity.
- An incorrect Activity Name configured by the administrator.
- The device being left idle.
- An unaddressed third-party application permission dialog that times out.
- Application Not Installed: If an administrator configures a sharing application that is missing from the device, the following error is displayed: “The following packages are not currently installed on the device: [Application Package Name]. Please contact the administrator.” The required application must be deployed to the device.
- User-Initiated Cancellation: If a user presses the back button while on the application selection screen, a confirmation dialog appears prompting them to either Cancel (to return to the selection screen) or Exit (to abort enrollment and return to the lock screen).
NFC Card (zCreator)
An NFC card can be used as a physical credential for authentication on Shared Devices, allowing for secure one-tap login and device unlock. The card is created using the zCreator companion app, which writes the user's profile to the card in an encrypted format that only Identity Guardian can read. The prompt to write user profile data to an NFC card appears during the Standard or Self-Enrollment process.
For successful authentication:
- The zCreator app must be installed on the devices. For guidance, see the Standard Enrollment or Self-Enrollment setup procedures.
- The card must comply with the NFC Card Specifications.
- The card must be held steady within 4 cm of the device's NFC reader for approximately 4 to 5 seconds.
Data Storage from Standard Enrollment
When using the Standard Enrollment process on a Shared Device, profile data is not written to a card immediately. Instead, the data is temporarily saved as an encrypted file within the zCreator companion app installed on the device. The saved enrollment file must be used to write to an NFC card within 24 hours. After this period, the temporary file is automatically deleted. To complete the process:
- After Standard Enrollment is finished, open the zCreator app on the device.
- Within 24 hours, follow the process to Write to NFC Card.
Admin Setup
Configure the following Managed Configurations:
- Enrollment Configuration:
- User Enrollment Configuration: NFC
- Shared Device Authentication:
- Comparison Source: NFC
Secure NFC and Key Management
For Secure NFC card deployment, refer to Secure NFC in the Setup guide for details on encrypted storage, read/write execution logic, zero-downtime key rotation, and required Managed Configurations.
Write to NFC Card
If NFC data is saved during Standard Enrollment, it is temporarily stored in zCreator and must be written to an NFC card within the 24-hour storage period.
To write to an NFC card:
- Open zCreator.
- Tap to open the relevant NFC file that contains the user data.
- Tap and hold the NFC card against the device to write the data. Continue to hold the card in place until the writing process is complete.
- When successful, a confirmation message appears indicating that the data has been written successfully.
Note for New NFC Cards: A new NFC card may need to be erased prior to use.
![]() |
![]() |
![]() |
||
| Writing to an NFC card |
MIFARE Card Writing
Due to secure system checks and card variations, writing data to a MIFARE card requires 3 to 15 seconds.
- New Cards: Processing is rapid, typically completing in 2 to 3 seconds.
- Cards with Existing Data: The system must securely clear old data first, extending processing time up to 15 seconds.
Guidelines for a Successful Write:
- Hold the Card Steady: Place the card flat against the back of the device reader and maintain contact without movement.
- Wait for Confirmation: Do not remove the card prematurely. Keep it in place until the "Confirmation" screen appears or the device vibrates.
- Handling Failures: If the card is moved too early, tap the retry button and hold the card still until the Confirmation Screen displays.
Sign In (Authentication)
After a user has been enrolled or configured for Zebra DNA Cloud-based authentication, the device displays the sign in screen. This screen also appears in response to specific Lock-screen Event triggers configured by the administrator, such as user sign-out, device lock, or system reboot.
To sign in or authenticate to a device, users can perform one of the following actions:
- Scan their user barcode.
- Tap their NFC card on the device.
- Tap Unlock on the screen.

The device prompts the user to authenticate based on the Authentication Configuration (Shared Device or Personal Device) set by the administrator. The authentication process follows these steps:
- Comparison Source: If applicable, the system first prompts the user to verify their identity using a comparison source, such as scanning their barcode or tapping their NFC card.
- Primary Authentication: After the comparison source is validated (if required), the system presents the user with the designated primary authentication method, such as entering a passcode or scanning their face.
- Secondary Authentication: If the primary authentication fails, the system prompts the user to complete the secondary authentication method.
- Fallback Authentication: If both the primary and secondary authentication methods fail (or if no secondary authentication is configured), the system presents the fallback authentication method.
For devices without a valid license, the system displays a passcode entry screen.
Note: A demo mode message will appear on the Identity Guardian lock screen if devices are not provisioned with the organization’s own encryption keys for user enrollment and authentication. This applies to shared device environments where the authentication scheme includes a barcode combined with facial biometrics or a user PIN/passcode.
Note: If a user logs in using their ZDNA Cloud Passcode while the device is offline, any credential updates made by an administrator will not sync until the current session ends or the user logs out. Example: If an administrator deactivates an account while the device is offline, the user can continue to unlock the device with their current PIN for up to 12 hours.
Microsoft Authenticator
If Microsoft Authenticator app is in use, perform the following after the user unlocks the screen:
- The Microsoft Authenticator app is launched prompting for user authentication. Enter the login credentials:
![]() |
![]() |
- After authentication is successful, the user gains access to the device.
- When a user launches any app that utilizes Microsoft Authenticator app as broker, the app automatically signs in without prompting for user name or password.
Suppress Camera Preview
This feature allows an administrator to suppress (hide) the camera preview during face authentication for increased user privacy. When enabled, the live video feed is replaced with a green smiley face icon that provides real-time feedback on face alignment. The end-user authenticates without seeing their own image on the screen. If the camera cannot capture the user's face, a yellow neutral face is displayed.
Admin Setup
Configure the following parameter within Managed Configurations:
- Facial Authentication Configuration:
- Suppress Camera View: On
- Save and deploy the configuration.
Usage
While a user authenticates using their face, a face icon appears instead of the live camera view. The icon's color indicates the quality of the scan:
Green Smiley: The user's face is properly framed and detected. Authentication can proceed.


Samples of green smiley face status icon displayed during facial capture Yellow Neutral Face: The camera is having trouble getting a clear capture of the user's face. To resolve this, the user should:
- Center their face in the camera's view.
- Hold the device steady and remain still.
- Adjust the angle or distance of the device.


Samples of yellow neutral face status icon displayed during facial capture
Unified Lock Screen (Keyguard)
Identity Guardian (IG) streamlines device access, providing a secure, user-friendly interface that unlocks the device in a single, seamless step. By integrating with Android's Keyguard framework, this feature inherits the full security of the native device lock screen while providing a smooth user experience, eliminating the need for the user to interact with a separate Android lock screen.
This approach satisfies corporate security policies that mandate the native Android device lock, while ensuring the user interacts only with the Identity Guardian interface for authentication.
Important: For this feature to work, meet all requirements and prerequisites.
Requirements & Prerequisites:
- OS Version: Android 14
- Supported Devices (to identify devices by platform, see Zebra Platform Devices):
- QC6490 Platform:
- Supported Devices: All
- Required LifeGuard Update: v14-35-10.00-UG-U56 (January 2026) or newer
- SM6375 Platform:
- Supported Devices: All devices except TN28
- Required LifeGuard Update:
- TC15: v14-09-18.00-UG-U245-STD-GRT-04 (January 2026) or newer
- ET40/ET45: v14-09-18.00-UG-U245-STD-GSE-04 (January 2026) or newer
- QC5430 Platform:
- Supported Devices: All devices except EM45 and KC50
- Required LifeGuard Update: v14-35-10.00-UG-U56 (January 2026) or newer
- Note:
- Prior to June 2026 LifeGuard Updates: When suspending and resuming the device, the Identity Guardian lock screen displays immediately with the Unlock button.
- June 2026 LifeGuard Updates and Later: When suspending and resuming the device, the Android swipe screen displays first. Swiping on this screen launches the Identity Guardian lock screen with the Unlock button.
- QC6490 Platform:
- Scope: Applies only to user authentication (not enrollment) on both Personally Assigned and Shared Devices.
- Device Configuration: The native Android lock screen must be enabled with a PIN, pattern, or password. Note: "None" or "Swipe" to unlock are not supported.
Compatibility Warning: The SSO Session Persistence feature (under SSO Authentication in Managed Configurations) is not supported when this Keyguard integration is enabled.
Admin Setup
Configure the Managed Configurations based on deployment type: Shared Device or Personal Device.
- Usage Mode:
- Application Mode: Select Personally Assigned or Authentication (for shared devices)
- Keyguard: Enable this option to replace the Android lock screen with the Identity Guardian lock screen.
- Select one of the following based on the device authentication:
- Shared Device Authentication: For each Verification Setup, define the following:
- Comparison Source: Select Barcode (Shared Device)
- Primary Authentication Factor: Select Face or Passcode.
- Secondary Authentication Factor: Select Face, Passcode, or SSO
- Fallback Authentication Method: Select Face, Passcode, or Admin Bypass Passcode
- Lock-screen Event Options: (Required) For the On Unlock event, assign a profile for Verification Setup and Alternate Verification Setup. These cannot be set to "None."
- Personal Device Authentication:
- Primary Authentication Factor: Select Android Lock, Face or Passcode.
- Lock-screen Event Options: (Required) For the On Unlock event, assign a profile for Verification Setup. This cannot be set to "None."
- Shared Device Authentication: For each Verification Setup, define the following:
- Self-Enrollment (Only for SSO): For Shared Devices using Self-Enrollment with SSO, Zebra strongly recommends setting a Corporate PIN under Enrollment Configuration for enhanced security; see Managed Configuration.
- Save and deploy the configuration.
Note: Enabling or disabling the Keyguard option in Managed Configurations automatically triggers a device reboot upon deployment.
Usage
The user experience differs for the very first unlock after configuration deployment and all subsequent unlocks.
First-Time Unlock (Immediately After Reboot):
- When the devices wakes after reboot, the user must first unlock it using their pre-configured Android PIN, pattern, or password.

- A notice appears indicating that Identity Guardian is preparing for user enrollment, followed immediately by the Identity Guardian lock screen. The user must then authenticate based on the configured device mode:
- Shared Device: The user authenticates using their Face, Passcode, or other configured Identity Guardian credential.
- Personal Device: The workflow depends on the user's enrollment and Enable SSO state (under Personal Device Authentication):
- If not enrolled: The user is guided through the enrollment process.
- If enrolled with "Enable SSO" set to "true": The SSO login page prompts the user for their credentials. Upon successful entry, the login is completed, and the credentials securely stored.
Note: If the user presses the back button on the SSO login page, the Identity Guardian lock screen appears with the Unlock button. Tapping this button relaunches the SSO login page. - If enrolled with "Enable SSO" set to "false": The user authenticates using their Face, Passcode, or other configured Identity Guardian credential.
Sample screen for Android PIN entry
Note: If an error occurs during enrollment with Keyguard enabled, or if the device gets stuck on the "Preparing for user enrollment" screen, the user must reboot the device to complete enrollment.
Normal Device Unlock (All Subsequent Unlocks):
After the initial setup is complete, the process becomes a seamless, single step.
- Each time the user wakes the device, only the Identity Guardian lock screen appears.
- The user authenticates with their configured Face, Passcode, or other Identity Guardian credential(s) to unlock the device. The native Android lock screen is completely bypassed.
Device Lockout & Failed Attempts
To prevent unauthorized access, the system initiates a temporary lockout after five (5) cumulative failed attempts. This section applies exclusively to Shared Devices, explaining how the failure counter accumulates and resets.
(Note: Personally Assigned Devices do not support Secondary or Fallback Authentication Factors.)
| Stage | User Action | Device Screen |
|---|---|---|
| 1. Identity Guardian (IG) Lock Screen | 5 consecutive failed Identity Guardian (IG) authentication attempts. The types of failures that contribute to this count depend on the authentication stage:
Secondary and Fallback (from Secondary): • Invalid passcode • Timeout for Face capture • SSO login is cancelled by pressing the back button and confirming the cancellation. Note: Tapping the Back button during Secondary or Fallback (from-Secondary) authentication resets the failure counter. |
The user is now required to enter their device PIN, pattern, or password. When successful, the device returns to the Identity Guardian lock screen. This sample screen capture shows the PIN entry:![]() |
| 2. Android Lock Screen | Successful Entry: The user enters the correct Android credentials. | The device returns to the Identity Guardian lock screen.![]() |
| Repeated Incorrect Entries: The user enters incorrect Android credentials 5 consecutive times. | The device proceeds to a Device Timed Lockout (Stage 3). | |
| 3. Device Timed Lockout | 5 consecutive failed Android lock screen attempts (from Stage 2). | The device becomes locked for a 30-second countdown, during which no input is accepted. This screen shows a sample of the device timed out screen for a PIN entry:![]() After the timer expires, the user is prompted again for their Android PIN, password, or pattern. When successful, the Identity Guardian lock screen is displayed. |
| Access Regained | Successful entry of Identity Guardian credentials at any stage. | Authenticate with IG credentials to unlock the device. The failed attempt counter is reset. |
Notes on Usage Behavior:
- Momentary Lock Screen: A brief flash of the native Android lock screen may appear before the Identity lock screen if the device is quickly suspended and resumed with a quick power button press (less than 2 seconds).
- SSO Authentication: Users should avoid suspending the device via the power button while on the SSO login screen, as this may disrupt the flow and require restarting authentication.
- Recovery After Disabling Android Lock: If a user changes the Android device lock from a secure method (PIN, pattern, or password) to a non-secure one ("None" or "Swipe"), the Identity Guardian Keyguard feature no longer operates. Simply re-enabling the secure lock does not fix it. To restore the feature, the admin must disable the Keyguard setting in the Identity Guardian profile via EMM and deploy the change, then re-enable the Keyguard setting and re-deploy the "enabled" configuration change.
- Authentication Delay: Users may experience an authentication delay of approximately 2 seconds in the following scenarios:
- After scanning a barcode when the subsequent authentication step is:
- Primary Authentication: Face or Passcode
- Fallback Authentication: Face, Passcode, or Admin Bypass Passcode
- During Admin Bypass Passcode authentication.
- During Self-Enrollment:
- When entering the Corporate PIN.
- Before the SSO screen appears, if the Corporate PIN feature is disabled (from Enrollment Configuration)
Alternate Authentication Key
The Alternate Authentication Key feature is designed to ensure seamless security certificate rotation without any downtime for users. It creates a transition period where enrollment barcodes from both an old and a new certificate are active simultaneously.
When an organization rotates its security certificate, a new private key is generated. An administrator can add this new key to the Alternate Authentication Key field while keeping the original in the Authentication Key field. During this period, users can log in with barcodes generated from either key, ensuring uninterrupted access. To complete the transition, the administrator simply removes the old, phased-out key.
Admin Setup
Configure Managed Configurations:
- Shared Device Authentication: Identity Guardian provides two functionally identical fields for encrypted private keys derived from your organization's security certificates.
- Authentication Key - The primary field for an encrypted private key.
- Alternate Authentication Key - The secondary field to facilitate certificate rotation.
- Save the changes and deploy them to devices. Once deployed, the system accepts enrollment barcodes generated from any key present in the configuration.
Deactivating an Old Certificate:
After confirming the new certificate is working and users have transitioned, remove the old one:
- Remove the Old Key: Remove the value from the field corresponding to the old key (Authentication Key or Alternate Authentication Key).
- Deploy the Configuration: Save and redeploy the configuration. After deployment, the system only accepts barcodes corresponding to the remaining (new) key. The administrator is responsible for notifying users when an old barcode is deactivated.
Note: In ZDNA Cloud, deactivating a key does not automatically remove the users associated with the old barcodes. These users must be manually removed from the system using the enrollment ID from their barcode.
Usage
On the device lock screen, scan the enrollment barcode. The device grants access if the barcode corresponds to any active authentication key currently configured on the device.

Note: If Guardian Safe is enabled, the user is prompted to save their credentials for future logins after successfully using a barcode from a newly added authentication key.
Prioritize Authentication Methods
Identity Guardian offers flexible user authentication methods triggered by various lock events, as configured by the administrator in the Lock-Screen Event Options under Shared Device Authentication. When a shared device experiences multiple simultaneous lock events, Identity Guardian selects the most secure Verification Setup based on the highest score from its weighted scoring system. This ensures the highest level of security for shared devices, even during concurrent events. The relevant Lock-Screen Event Options include:
- On Unlock
- On AC Power Connected
- On AC Power Disconnection
Note: The priority logic does not apply to other lock screen events: On Reboot, On Device Manual Checkin (user logout), and On User Change. In these scenarios, Identity Guardian selects the specific Verification Setup configured by the administrator for that event to authenticate the user.
Weighted Scoring System
Identity Guardian uses a weighted scoring system to determine the optimal Verification Setup for simultaneous lock events on a shared device. Each authentication factor is assigned a specific weight:
| Authentication Factor | Weight (Score) |
|---|---|
| SSO | 4 |
| FACE | 3 |
| PASSCODE | 2 |
| NO_COMPARISON | 1 |
| NONE | 0 |
The total score for a Verification Setup is calculated by summing the scores of its primary and secondary authentication factors. The setup with the highest score is deemed the most secure and is selected for implementation. Fallback authentication methods do not contribute to the total score.
Example
Consider the following administrator configurations:
- Verification Setup 1:
- Primary Authentication Factor: FACE
- Secondary Authentication Factor: PASSCODE
- Fallback Authentication Method: ADMIN BYPASS PASSCODE
- Verification Setup 2:
- Primary Authentication Factor: FACE
- Secondary Authentication Factor: NONE
- Fallback Authentication Method: NONE
The scores for these setups are calculated as follows:
| Verification Setup | Primary Authentication Factor (Score) |
Secondary Authentication Factor (Score) |
Fallback Authentication (No Score) |
Total Score |
|---|---|---|---|---|
| Setup 1 | FACE (3) | PASSCODE (2) | ADMIN BYPASS PASSCODE | 5 |
| Setup 2 | FACE (3) | NONE (0) | NONE | 3 |
Scenario: If Verification Setup 1 is configured for an unlock event and Verification Setup 2 is configured for a power disconnection event, and both events occur sequentially (e.g., unlock followed by power disconnection) while the user is logged in with the device, Identity Guardian will prioritize Verification Setup 1. This decision due to Setup 1's higher total score (5) compared to Setup 2's score (3), demonstrating Identity Guardian’s approach to selecting the verification setup with the highest combined security weight.
Non-Identity Guardian Barcode
A user barcode, known as a Legacy Barcode, can be used to authenticate users even if it was not generated by Identity Guardian. This is useful in organizations where user barcodes already exist. These barcodes must be 1D and have a defined prefix. Upon scanning, the prefix is disregarded, and the user name serves as the identifier. When the device is locked, the user name is prominently displayed on the lock screen.
Note: Legacy Barcode is not encrypted and, therefore, not secure. For shared devices, Zebra recommends using encrypted barcodes for secure authentication. See Managed Configurations for more information.
Admin Setup
Configure Managed Configurations:
- Shared Device Authentication - Expand User Verification Methods:
- Verification Setup
- Enable Comparison Source and select LEGACY BARCODE.
- Under Primary Authentication Method:
- Enable Primary Authentication Factor and set this to NO_COMPARISON.
- Enable Secondary Authentication Factor and set this to NONE.
- Enable Fallback Authentication Method and set this to NONE.
- Legacy Barcode Options:
- Enable Legacy Barcode Prefix and enter the prefix used to validate the barcode. The barcode must begin with this prefix, otherwise the user will not be authenticated. Without a prefix, the user will not be authenticated.
- Verification Setup
- Save the changes and deploy them to the devices.
Usage
- On the lock screen, tap the Scan to Unlock button.

- Scan the user barcode. The user gains access to the device.

- Lock the device. The user name is displayed in the lock screen.

Admin Bypass
A user can bypass authentication by entering the Admin Bypass Passcode, useful for situations where authentication credentials are forgotten. Access is granted provided the user has received the bypass passcode from an admin. While this feature allows device access, it does not track user accountability. It offers a direct method to enter the passcode, as opposed to the alternative fallback authentication (part of the Shared Device Authentication scheme), which requires multiple failed authentication attempts.
As a security measure, user login attempts are initially limited to five. A message appears indicating the remaining attempts. If all attempts are used, the user is advised to wait five minutes before trying again and the option is not accessible until the time elapses. Subsequent failed attempts or device reboots restrict the user to a single failed attempt before the device is locked again for five minutes. If the admin disables the Admin Bypass option, the login attempt counter resets to five for the initial login attempt.
![]() |
![]() |
|
| Message indicating the remaining number of failed attempts |
Message indicating the maximum number of allowed attempts is reached |
Admin Setup
Configure Managed Configurations:
- Lock Screen Configuration: Expand Lock-screen Menu.
- Enable Enable Admin Bypass Passcode on Lock screen and set it to true.
- Save the changes and deploy them to the devices.
Usage
- In the lock screen, tap the menu icon in the top right corner and select Admin Bypass.

- Enter the Admin Bypass Passcode provided by your administrator and tap Unlock.

- The user gains device access.
Alternate Sign-In
Alternate Sign-In, also known as Alternative Login, enables users of shared devices to log in as different users. This feature is useful for scenarios involving temporary users or those who do not have full-time access, ensuring user accountability is tracked.
Note: The user must be enrolled on the device before using the alternate sign-in method.
Admin Setup
Configure Managed Configurations:
- Shared Device Authentication - Expand Lock-screen Event Options:
- On Unlock / OnReboot / On AC power connected / On AC power disconnected / On device manual checkin / On user change
- Enable Alternative Verification Setup and select the desired Verification Setup that specifies the authentication required for the alternate login.
- On Unlock / OnReboot / On AC power connected / On AC power disconnected / On device manual checkin / On user change
- Lock Screen Configuration - Expand Lock Screen Menu:
- Enable Customize Alternative Login Button and enter a name for the button designated for alternate login.
- Save the changes and deploy them to the devices.
Usage
- On the lock screen, tap the button with the customized text located above the Unlock button. The text on this button is based on the admin configuration.

- Scan the user barcode and perform facial authentication.
- The user gains device access.
Auto-Fill SSO Login
When users sign in with their Single Sign-On (SSO) credentials, they can save them for future device logins, simplifying the process by requiring password entry only once. After passes Primary Authentication (e.g., facial scan or passcode), their SSO user name and password are automatically filled for subsequent logins.
This feature is available only when SSO is used as the Secondary Authentication method (Fallback Authentication is not supported).
The SSO credentials are stored and managed in Guardian Safe. Even if Guardian Safe is disabled, users can still access these credentials, though only the SSO credentials are visible. Designated with the IG logo, these credentials are intended exclusively for use with Identity Guardian. Auto-filling of SSO login credentials occurs at the device level during authentication (managed by Identity Guardian) and when logging into Guardian Safe.
Important Notes:
- User Barcode - Must be generated with Identity Guardian v1.6 or later.
- SSO User ID - The SSO user ID is case-sensitive — the string entered during user enrollment must exactly match that from the identity provider. Discrepancies may lead to authentication issues or failure.
Admin Setup
Configure Managed Configurations:
- Choose one of the following configurations based on the device deployment model:
- Shared Device Authentication:
- Primary Authentication Factor: FACE or PASSCODE
- Secondary Authentication Factor: SSO
- Personal Device Authentication:
- Primary Authentication Factor: ANDROID_LOCK
- Enable SSO: true
- Shared Device Authentication:
- In Guardian Safe Configuration:
- Auto Fill for SSO: ENABLE
- Automatically Grant Accessibility Permission: ENABLE
- In SSO Authentication Configuration, configure the SSO settings as needed.
- Save the changes and deploy them to the devices.
Usage
- On the lock screen, scan the user barcode.

- Proceed with one of the following options based on the administrative configuration for Primary Authentication Factor:
- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."

- Facial biometric authentication: Scan the user's face. This applies if the Primary Authentication Factor is set to "FACE."
- Passcode entry: Enter the user-defined passcode. This applies if the Primary Authentication Factor is set to "PASSCODE."

- Android lock screen credential: Enter the device PIN, pattern, or password. This applies if "Keyguard" is enabled and the Primary Authentication Factor is set to "ANDROID_LOCK."
- The SSO login screen, as the secondary authentication method, appears with the user name field populated. Tap the password field.

- The user is prompted to save their credentials. Tap Yes to save credentials for future logins.

- Enter the user password and tap Save Credentials.

- The SSO login page reappears with the user name populated. Tap the password field to auto-fill the password, streamlining future logins.
SSO Temporary ID
SSO Temporary ID simplifies authentication on shared devices. After a single initial SSO sign-in, users can gain secure, uninterrupted access throughout their shift by using a temporary PIN or biometrics for subsequent logins. This eliminates the need to repeatedly enter primary login credentials or use physical credentials such as barcodes or NFC cards.
At the start of a shift, a user authenticates once with their primary SSO credentials. For all subsequent logins during that shift, they can use one of the following quick and convenient temporary methods until they logout at the end of their shift:
- PIN Code - A simple, user-defined numeric code for quick entry.
- Biometrics - Instant facial recognition for seamless, touchless authentication.
Key Benefits:
- Streamline Workflow - Replaces repetitive SSO logins with instant PIN or facial biometric access, allowing users stay focused on their tasks.
- Personalized Login - Provides temporary, user-specific access without carrying physical credentials.
- Maintain Security - Ensures device access remains tied to an authenticated individual, even in a shared environment.
Requirements:
- Hardware: Facial recognition requires a device with a front-facing camera.. Devices without a camera can still use PIN authentication.
- SSO Setup: Identity Guardian must be integrated with your identity provider (IdP); see SSO Setup.
- Licensing: An Identity Guardian license is required for full functionality.
- Note: On devices with only a Device Guardian license, functionality is limited to PIN authentication; facial recognition is disabled.
Admin Setup
Configure Managed Configurations:
- In Shared Device Authentication, set the primary authentication to SSO as follows:
- Comparison Source: NONE
- Primary Authentication Factor: SSO
- Secondary Authentication Factor: NONE
- Fallback Authentication Method: NONE or ADMIN BYPASS
- In SSO Authentication Configuration, enable continuous login via Temp Id:
- Temp Id: true
- Authentication Mode: [Select the desired mode, e.g. PIN, FACE, or ANY.]
- Temp Id Type: [Select Numeric or Alphanumeric.]
- Minimum Length: [Select the minimum total character length.]
- Minimum Uppercase Letters: [Select 1 to require uppercase letters or 0 to make them optional.]
- Minimum Lowercase Letters: [Select 1 to require lowercase letters or 0 to make them optional.]
- Minimum Numbers: [Select 1 to require numbers or 0 to make them optional.]
- Minimum Special Symbols: [Select 1 to require special symbols or 0 to make them optional.]
- Save and deploy the changes.
Usage
The SSO Temporary ID feature simplifies access after an initial one-time setup. The user workflow is divided into two main phases: initial enrollment and subsequent logins.
First-time Login:
This is the one-time process for setting up the expedited authentication method.
The user logs in for the first time using their standard SSO credentials. On the lock screen, tap Unlock.

Enter the user credentials and login.

Upon successful authentication, the system prompts the user to enroll with a temporary ID. Tap Continue.

The user follows the on-screen instructions for enrollment. The authentication options presented are determined by their administrator's settings. The user may be directed to set up a specific method or be given a choice to select from the available options (PIN ID or Face ID).

The user follows the on-screen instructions based on their selected method or the method setup by their admin:
- PIN Code - The user creates a numeric PIN based on the rules defined by the administrator.

- Biometrics - The user taps Add, accepts the terms and conditions, and then completes the on-screen facial capture process.



- PIN Code - The user creates a numeric PIN based on the rules defined by the administrator.
When complete, tap Continue to gain access to the device.

Subsequent Logins:
On all subsequent logins on the same device, the experience depends on whether the user has enrolled:
- If Enrolled: The user is prompted for their PIN or Facial Biometric scan.
- A successful authentication unlocks the device instantly.
- If authentication fails, the user can retry. After a configured number of failed attempts, the temporary ID is cleared, and the user must log in again with their full SSO credentials to re-enroll.
- If Enrollment Was Skipped: The user must authenticate using their standard SSO credentials each time. They will continue to be prompted to enroll after each successful SSO login.
Logout and Session Clearing:
To maintain security on shared devices, the temporary credentials are automatically cleared upon user logout or when switching users:
- Upon Logout: The user's PIN or Face ID is cleared from the device.
- Next Login: The next user must log in with their standard SSO credentials and can then enroll in Continuous SSO Login for their own session.
Lockout Mechanism:
To prevent unauthorized access, the system clears the temporary ID from the device after five (5) consecutive failed login attempts (either PIN or Face). The user is then forced to re-authenticate using their standard SSO credentials.
Profile Management
Users can manage their SSO Temporary ID settings through their Identity Guardian user profile settings. This includes changing or deleting their PIN or facial capture.
To access these settings, open Identity Guardian, tap the menu icon in the top right corner and select IG Temporary ID.
![]() |
![]() |
Access PIN or Facial Settings
PIN Code Options:
View Status: Check if a PIN is currently active.
Add PIN: Setup a new PIN if one is not already set up.
Delete PIN: Remove the PIN after user confirmation.
Change PIN: Modify the existing PIN. When prompted:
- Enter the current PIN (an alphanumeric keypad always displays, even for numeric PINs).
- Enter the new PIN and confirm the entry. The displayed keypad (numeric or alphanumeric) corresponds to the configured PIN type setting.

PIN code options
Facial Recognition Options:
- Add Face: Enroll facial data if not already enrolled. This option is only available when adding facial data for the first time or after deleting existing facial data.

- Delete Face: Remove the existing enrolled facial data.

Default SSO Domain
Configure the Default SSO Domain to streamline user authentication for Microsoft Entra ID SSO by eliminating the need to manually enter the domain during login. The user only needs to type the username, and the default domain is automatically applied.
Admin Setup
Configure the following Managed Configuration:
- Under SSO Authentication Configuration, enter the value for Default Domain.
- Save the changes and deploy them to the devices.
Usage
- On the lock screen, tap Unlock.
- Enter the username (excluding the domain) and password when prompted.
- Tap Sign in.

Default SSO Domain Workflow
Proxy Mode
Proxy Mode allows a third-party screen-blocking application (e.g. Imprivata, Workspace ONE) to replace Identity Guardian's native screen blocking. In this mode, the third-party app relays device events (like user sign-in/sign-out) through Identity Guardian to registered Line of Business (LOB) apps or Zebra apps like Device Tracker for centralized user accountability.
Note: When Proxy Mode is active, attempting to launch the Identity Guardian app directly displays a message indicating that it is not intended to be launched in its current configuration.
Admin Setup
Configuring Proxy Mode requires preparing the third-party app, setting the Identity Guardian Managed Configurations, and deploying the changes.
- Install the third-party screen blocking app (e.g., Imprivata).
- Optional: Install the Zebra app (e.g. Device Tracker) or LOB app designated to receive user session information.
- Implement application logic based on the third-party screen-blocking app in use:
- Imprivata - To receive events, register for the Get Lock Screen Status API to monitor SHOWN/HIDDEN states of the Imprivata lock screen state, or register for the Current User Session API to track user sign-in/sign-out events and retrieve user details.
- Workspace ONE - To receive events, register for the Current User Session API to listen for user sign-in/sign-out events and retrieve user details.
- All Other Custom Apps - The custom screen-blocking app must integrate with the Current Session API. Set the
signed_in_statetotrueon user sign-in andfalseon sign-out.
- Configure Managed Configurations:
- In Usage Mode, set the following:
- Application Mode: Proxy
- In Shared Device Authentication, set the following:
- Preferred Authentication App: Imprivata or Workspace ONE (Note: Enter only one based on the third-party app in use.)
- In Usage Mode, set the following:
- Save the configuration changes and deploy them to the devices.
Warning: When utilizing Imprivata as the preferred authentication app, Usage Mode must be set to Proxy. Configuring Authentication or Personally Assigned mode results in a continuous authentication loop between the two applications, preventing the user from accessing the device.
Usage
User Sign-In/Sign-Out Events:
When a user signs into or out of the third-party screen blocking app, Identity Guardian receives the event and relays it to other listening applications, which can then take action. The table below describes the resulting behavior in Device Tracker as an example.
| User Action | Example Behavior in Device Tracker |
|---|---|
| Sign-In | The user's name populates the Checked Out field. |
| Sign-Out | The user's name is cleared from the Checked Out field. |
Imprivata-specific Events:
For Imprivata integrations, Identity Guardian also notifies the registered LOB app of device lock/unlock state changes through the JSON response from the Register For Notifications API.
Brute-Force Protection
Brute-Force Protection is a security mechanism designed to prevent unauthorized access on shared and personally assigned devices. It deters brute-force attacks by implementing a tiered delay system that progressively increases the lockout duration after consecutive failed unlock attempts. This protects the device from persistent attacks while maintaining usability for legitimate users who may accidentally mistype their credentials
Key Capabilities:
- Progressive Delay System: Increases the delay time after each configured level is reached.
- Multiple Lockout Levels: Supports up to 3 distinct authentication delay levels.
- Customizable Settings: Allows administrators to define the retry count and delay duration for each level.
- Device State Management: Enforces the Auth-Lock State to restrict system access during the lockout duration.
- Admin Bypass Option: Allows administrators to immediately clear the Auth-Lock State using an Admin Bypass Passcode.
Auth-Lock State
When a configured failure threshold is reached, the device enters the Auth-Lock State. This protected device state temporarily prevents user authentication for a configurable duration. During this state:
- Users cannot authenticate or unlock the device.
- The configured delay timer is enforced on the lock screen.
- The state clears only when the delay duration expires or a valid Admin Bypass Passcode is entered.
System Reboot and Android Lock Screen (Keyguard) Behavior:
- Rebooting without Keyguard: When the device is in the Auth-Lock State with the countdown timer running, rebooting the device does not reset the timer. After the reboot, the countdown timer continues decreasing from the exact point of interruption.
- Rebooting with Keyguard Enabled: If the system Keyguard is enabled, the countdown timer remains paused while the device is on the Keyguard lock screen after a reboot. The time spent on the Keyguard screen does not count toward the countdown period. For example: If a 1-minute countdown is interrupted by a device reboot, and the device remains on the Keyguard screen for 5 minutes before the user unlocks it, the countdown timer ignores those 5 minutes and resumes decreasing from the exact point it was interrupted prior to the reboot.
Note: Brute-Force Protection only applies to Passcode, Cloud Passcode, and Admin Bypass Passcode Fallback Authentication Methods. It is not supported for SSO, Face Authentication, or Guardian Safe.
Recommended Lockout Strategy
The progressive lockout feature supports up to three escalating levels. The following strategy outlines how to configure these tiers to create a balanced, highly secure protection policy.
Level 1 Configuration: The Initial Lockout
This level acts as the first line of defense against casual guessing or user error.
Configuration: Set a moderate failure count threshold (e.g., 5 attempts) paired with a very short delay (e.g., 30 seconds).
Outcome: After 5 failed attempts, the device enters the Auth-Lock State. A lock screen displays a 30-second countdown timer. A 30-second wait is required before attempting to log in again. Any subsequent failures trigger the same 30-second delay.
Purpose: This brief timeout slightly delays an attacker without severely impacting a legitimate user who simply mistyped a passcode.

Level 2 Configuration: The Escalated Lockout
This level activates if incorrect attempts continue immediately following the Level 1 lockout, indicating a persistent attack.
Configuration: Set an additional failure count threshold (e.g., 6 consecutive attempts after the Level 1 threshold) paired with a significantly longer lockout duration (e.g., 900 seconds, or 15 minutes).
Outcome: After the first 5 failed attempts, the device locks for 30 seconds (Level 1). If the user fails 6 more times consecutively after the first tier, the device locks for 15 minutes (Level 2). Any further failures continuously apply the 15-minute delay.
Purpose: This moderate-to-long delay drastically slows down manual or automated brute-force attempts, making it impractical for an attacker to quickly guess credentials.
Level 3 Configuration: The Maximum Lockout
This is the final and most severe tier, triggered if failures persist despite the previous two lockouts.
Configuration: Maintaining the previous two configurations, set a final failure count threshold (e.g., 6 consecutive attempts after the Level 2 delay expires) paired with a severe, maximum delay (e.g., 7200 seconds, or 2 hours).
Outcome: The first 5 consecutive failures lock the device for 30 seconds. The next 6 consecutive failures lock it for 15 minutes. The next 6 consecutive failures after that lock it for 2 hours. Any further failures continuously apply the 2-hour delay.
Purpose: This creates a strict security lockdown. Once Level 3 is triggered, any subsequent failed attempt continuously applies this maximum 2-hour delay, effectively stopping brute-force attacks while waiting for the delay to expire or for an administrator to intervene using an Admin Bypass Passcode.
Admin Setup
Configure the following Managed Configurations through the EMM console or Zebra DNA:
- In Security Settings, set the following:
- Prevent Brute Force Attack: ENABLE
- Number of Levels: [Select 1, 2 or 3 based on organizational requirements.]
- Level 1 Settings: Applies if Number of Levels is set to 1 or higher.
- Failed Count: [Select the required failure count threshold.]
- Delay Time: [Select the desired delay time for each failure.]
- Level 2 Settings: Applies if Number of Levels is set to 2 or higher.
- Failed Count: [Select the required failure count threshold.]
- Delay Time: [Select the desired delay time for each failure.]
- Level 3 Settings: Applies if Number of Levels is set to 3.
- Failed Count: [Select the required failure count threshold.]
- Delay Time: [Select the desired delay time for each failure.]
- Optional: To allow the Auth-Lock State to be bypassed, in Lock Screen Configuration set Enable Admin Bypass Passcode on Lock screen to true.
- Save and deploy the changes.
User Authentication Scenarios
This video demonstrates various scenarios of user device authentication. In this example, one group of authentication settings is applied to a shared device with the following configurations:
- Comparison source: Barcode
- Primary authentication: SSO
- Secondary authentication: Passcode
- Fallback authentication: Admin bypass passcode
Account Lockout (Passcode)
Account Lockout tracks consecutive failed passcode sign-in attempts on Shared and Personally Assigned Devices. When the failed attempt count exceeds the configured limit, the system temporarily locks the user account for a pre-defined duration to protect against unauthorized access and brute-force passcode guessing.
Requirements:
- Zebra DNA Client must be installed on the device.
Limitations:
- Failed Passcode Entries Only: Account Lockout applies strictly to failed passcode entries. The system does not monitor or lock accounts based on failed biometric scans (e.g., facial recognition) or Single Sign-On (SSO) failures.
- Android Lock Incompatibility: Personally Assigned Devices do not support Account Lockout when the Primary Authentication Factor is set to ANDROID_LOCK in Personal Device Authentication.
- Keyguard Conflict: When Keyguard is enabled under Usage Mode on Personally Assigned devices, the default Android Lock is enforced. Because Identity Guardian passcode input is does not display, Account Lockout does not function in this scenario.
Admin Setup
EMM Managed Configuration Steps:
- Under Security Settings, enable Account lockout configuration.
- Set the desired settings:
- Enable account lockout after failed sign-in attempts: true
- Maximum failed sign-in attempts: [Select the number of failed attempts before locking the account.]
- Auto-unlock time for locked accounts: [Enter the number of minutes for the locked account to automatically unlock.]
Usage
- Failed Sign-In Attempt: Entering an incorrect passcode triggers a "Login Error" alert indicating the remaining number of permitted attempts.
- Account Lockout: Reaching the failure threshold locks the account and displays an "Account Locked" notification.
- Note: The lockout notification displays the remaining lockout period rounded to whole minutes and does not show an active countdown in seconds.
- Note: The lockout notification displays the remaining lockout period rounded to whole minutes and does not show an active countdown in seconds.
- Account Recovery: Access restores automatically once the configured timeout elapses, or an administrator manually unlocks the account through ZDNA Cloud prior to expiration.
Offline Login (No Network Connection)
Device login is supported even when WiFi or cellular network connections are unavailable. However, authentication methods requiring active network verification, such as Single Sign-On (SSO) or Cloud Passcode, are unavailable in offline mode.
Offline Login Procedure:
- Wake the screen and scan the user QR Barcode or tap the NFC Badge.
- When prompted, enter the designated Passcode or perform a facial scan (Facial Biometrics).
Delayed Account Lockout: Failed passcode attempts entered while offline are cached locally on the device. Once network connectivity is restored, these cached attempts sync to the administrative server:
- Exceeded Fail Limit: If the number of offline failed attempts exceeds the configured threshold, the device immediately locks and displays a "Device Locked" notification.
- Under Fail Limit: If the number of offline failed attempts remains below the threshold, standard device operation continues without interruption.
Temporary Home Screen Access During Lockout
Due to the brief latency required for a device to verify account status with the administrative server, temporary home screen access may occur during an active lockout.
- Behavior: If an account is already locked and a user enters the correct passcode, the home screen may temporarily open. However, as soon as the device verifies the active lockout status, the system immediately terminates the session, locks the device, and displays the "Account Locked" screen.
- Required Action: If the home screen opens temporarily during a lockout, do not initiate work tasks. The session will terminate automatically within a few seconds, resulting in a loss of unsaved progress. Stand by until the lockout timer expires, or contact the system administrator to unlock the device.
Sign Out
Sign Out only applies to shared devices. To sign out a device, perform one of the following:
- Open Identity Guardian app (Zebra Biometric) and tap Sign out.

- Swipe down to open the notification drawer. From the Identity Guardian notification, tap Sign Out.

- Lock the device.
- Restart the device (if configured by the administrator).
After a device is signed out, the lock screen is visible:

Auto Logout
The Auto Logout feature automatically signs out the user after the device has been idle for a specified period of time. This feature applies to Shared Devices only.The idle timer begins as soon as the screen turns off, which is triggered by either of the following events:
- The system Screen Timeout period elapses (configured in Android Settings > Display).
- The user manually presses the power button.
This feature applies to Shared Devices only.
Behavioral Notes:
- Device Reboot: The state of the Auto Logout timer is preserved across reboots.
- If the timer had already expired, the user is logged out immediately upon startup.
- If the timer had not expired, it resumes its countdown from where it left off prior to reboot.
- On Unlock Setting: When the On Unlock option under Lock-screen Event Options in Managed Configurations is set to NONE, the Auto Logout timer is terminated as soon as the user successfully unlocks the device, which effectively disables Auto Logout.
- Force Logout: If both Auto Logout and Force Logout (under Shared Device Authentication in Managed Configurations) are enabled, the logout is triggered by whichever condition is met first.
Admin Setup
Configure Managed Configurations:
- Lock Screen Configuration:
- Enable Enable Auto Logout After Timeout.
- Set the value for Auto Logout Timeout.
- Save the changes.
- Deploy to the devices.
Usage
- After a user logs in, the device functions normally.
- When the device becomes idle (due to screen timeout or power button press), the Auto Logout timer begins.
- Once the configured timeout period elapses, the user is automatically signed out. The login screen then displays with a blank User Name field, indicating successful logout.

Global Sign-Out
Global Sign-Out enables any applications using Microsoft Entra ID Single Sign-On (SSO) on shared devices to perform a universal logout across all supported apps. This feature clears previously signed-in accounts and displays the Identity Guardian lock screen. For example, if Microsoft Teams is installed, a user who logs into to the device with their Microsoft Entra ID credentials is automatically signed into the Teams app. With Global Sign-Out enabled, signing out from either Teams or Identity Guardian triggers the removal of user data and presents the Identity Guardian lock screen for the next user login.
Admin Setup
Prerequisites:
- Microsoft Entra ID is integrated with Identity Guardian as the SSO provider.
- The Microsoft Authenticator app is configured in Shared Device Mode.
- The Identity Guardian app is installed with SSO Authentication Configuration, presenting the Identity Guardian lock screen where users must enter their Microsoft Entra ID credentials to login.
To Configure "Global Sign-Out in Shared Mode":
- In Identity Guardian's Managed Configurations, select SSO Authentication Configuration.
- Enable Global Sign-Out in shared mode.
Usage
- Sign out of the device or sign out from any app with Microsoft Entra ID SSO.
- All user data is removed and the Identity Guardian lock screen is displayed for the next user login.
Clear Application Data
The Clear Application Data feature allows for the removal of application storage data, enabling business applications to reset to their default state and ensuring that subsequent users cannot access the previous user’s information. This feature is particularly useful when users log out or switch accounts. The reset is performed based on the application’s package name.
Important Note: The package name for Identity Guardian (com.zebra.mdna.els) cannot be added as an app for this feature. This restriction is in place to ensure that Identity Guardian operates without unintended disruptions.
Admin Setup
Steps to Configure "Clear Application Data" in Identity Guardian Managed Configurations:
Configure App:
- In Identity Guardian's Managed Configurations, select Shared Device Authentication.
- Locate the Logout Behavior section.
- Enable the Clear Application Data option.
Add Application Details:
- Click the Add Application Details button to display the field for entering the package name.
- Enter the application's package name. For example, to add Google Chrome, enter:
com.android.chrome. - To add more apps, click Add Application Details and repeat this process as needed.
- Use the Clear or Delete buttons to modify or remove any entries.
Save and Apply:
- Complete the remaining steps in the process, then save and apply the changes. This clears the specified application data whenever a user logs out or switches accounts.

Usage
- Sign out the device.
- The application specified is restored to its default state, deleting all user data and settings.
Wearable Devices
Identity Guardian provides an optimized user interface tailored for smaller form factor displays on supported Zebra wearable devices, such as the WS301 and WS501.
When deployed to a wearable device, the lock screen, authentication prompts, and session controls automatically adjust to provide streamlined interaction while maintaining enterprise security standards.
Key wearable capabilities include:
- Compact Lock Screen: Displays time, battery status, and direct-action buttons (Scan to Unlock, Tap to Unlock).
- Multi-Factor Authentication: Supports Barcode, NFC, Face (WS301 only), and Passcode verification.
- Session Management: Enables swift user switching, admin bypass, and quick device detail inspection.
For complete setup requirements, supported features, and step-by-step procedures, refer to the Wearable Devices guide.
Lock Device
This section discusses features designed to enhance user experience and security on the device lock screen.
Custom Message
A user can create a custom message to display on the lock screen, which can be useful in various scenarios. For shared device users, it allows them to leave instructions for the next user. For personally assigned device users, it can serve as a device identifier or a personal reminder. This custom message remains visible to all users when they sign in or sign out of the device.
Admin Setup
Configure Managed Configurations:
- Lock Screen Configuration - Expand Custom Lock Screen Message:
- Enable Allow Custom Lock Screen Message and set it to true.
- Enable Custom Lock Screen Message Source and select App Specific.
- Save the changes.
Usage
To create or edit a custom message on the lock screen:
- Sign in to the device to gain device access.

- Open Identity Guardian from the apps menu.

- From the top right, tap on the message icon to access the message settings.

- Enter the message to display on the lock screen, then tap Save.

- Lock the device. The custom message is now displayed on the lock screen.

Unlock via Face
Auto-Unlock seemlessly unlocks the device using facial authentication, eliminating need to tap a button on the lock screen. With this feature enabled, users are immediately prompted to scan their face for authentication when unlocking the device, bypssing the extra step.
Requirements:
- Face must be configured for primary authentication.
- For shared devices, Authentication Data Storage must be enabled (not required for personally assigned devices).
Admin Setup
Configure Managed Configurations:
- Lock Screen Configuration - Expand User Verification Methods:
- Verification Setup1:
- Enable Comparison Source and select BARCODE.
- Expand Primary Authentication Method. Enable Primary Authentication Factor and select FACE.
- Verification Setup1:
- Lock Screen Configuration - Expand Auto Unlock:
- Enable On Unlock and select true.
- Save the changes.
Usage
- On the lock screen, tap the unlock button:
- For shared devices: Scan to Unlock
- For personally assigned devices: Unlock

- Scan the user barcode and then scan the user's face for facial authentication. The barcode scan is needed for first-time authentication.
- The user gains access to the device.
Subsequent Unlock Attempts: When unlocking the device (e.g. pressing the power button or swiping to unlock), the user is immediately prompted to scan their face for authentication, bypassing the need to tap the unlock button.
Unlock via NFC/Barcode
On shared devices, signed-in users can resume an active, locked session by tapping the identical NFC card or scanning the same barcode used for initial sign-in. This eliminates the need for further authentication. If an active session exists with valid temporary authentication data, the device unlocks without requiring Face, Passcode, or SSO secondary authentication, or fallback authentication.
Note: The same employee or user ID paired with a different enrollment ID is treated as a completely different user.
Admin Setup
Configure the following required Managed Configurations settings:
- Usage Mode:
- Application Mode: Select Authentication.
- Shared Device Authentication:
- Authentication Data Storage: Set Store Authentication Data to true.
- Verification Setup1 (Initial Login):
- Comparison Source: Select NFC or BARCODE.
- Primary Authentication Factor: Select any option except NO*COMPARISON (such as FACE, PASSCODE, or SSO). *(This ensures a multi-factor credential check for the user's initial login.)_
- Verification Setup2/3/4 (Shift Unlock):
- Comparison Source: Select NFC or BARCODE.
- Primary Authentication Factor: Select USER_MATCH. (This allows the active user to quickly re-authenticate via a tap or scan, bypassing Secondary and Fallback Authentication.)
- Lock-screen Event Options:
- On Unlock: Select the specific Verification Setup that has the Primary Authentication Factor set to USER_MATCH (either Verification Setup2, 3, or 4).
- On User Change: Select one of the following to handle a tap or scan from a different user during an active session:
- NONE: Select this to reject other users' taps or scans. The device remains locked and displays an error message indicating a different user authentication attempt.
- Verification Setup1: Select this to allow a different user to initiate a new session by triggering a full authentication sequence.
- Save and deploy the changes.
Usage
On a locked device with an active user session, unlock the device by simpliy tapping the assigned NFC card or scanning the user barcode.
Microsoft SSO Session Persistence
The SSO Session Persistence feature allows user sessions to be retained for those logging in with Microsoft as their identity provider (using Microsoft authenticator as the broker app). This means that after locking the device, users can unlock it and log in by simply entering their password, since their user name is retained.
Requirements:
- Shared Device Authentication: Verification Setup must be configured only with SSO as the primary authentication factor, with no secondary or fallback methods.
- Lock Screen Events: All Lock Screen Events (both main and alternative) should use the Verification Setup that is configured solely with SSO, as specified in the previous requirement.
Admin Setup
To enable Microsoft SSO Session Persistence, configure the following Managed Configurations:
- Usage Mode:
- Enable Application Mode and set it to Authentication.
- Shared Device Authentication - Expand User Verification Methods. For Verification Setup:
- Enable Primary Authentication Factor and set it to SSO.
- Enable Secondary Authentication Factor and set it to NONE.
- Enable Fallback Authentication Method and set it to NONE.
- SSO Authentication Configuration:
- Enable Single Sign On Provider and set it to Microsoft.
- Enable SSO Session Persistence and set it to true.
- Enable Lock-screen Event Options. Select the desired options, ensuring the Verification Setup solely includes SSO for both main and alternative setups, as stated in the Requirements section. NOTE: The On Reboot option does not apply to SSO Session Persistence. After a device reboot, the lock screen appears based on the selected Verification Setup.
- Save and deploy the changes.
IMPORTANT: When a deployment with the SSO Session Persistence value set to true is processed by the EMM system to the device, Identity Guardian reviews the Verification Setups configured for Lock Screen Events. If any of these setups incorporate non-SSO factors, a warning message is sent to the EMM system, indicating that SSO persistence is supported only for configurations that use SSO exclusively.
Usage
This section discusses how to use the Microsoft SSO Session Persistence feature.
When a lock event occurs after logging into Microsoft SSO, the “Switch User” and “Unlock” buttons appear on the screen. Proceed with one of the following actions:
- Tap Unlock - The user is prompted to enter their password, with the username automatically populated from the existing Microsoft user session.

- Tap Switch User - The user is redirected to the lock screen according to the associated Verification Setup. Any interaction with the buttons on the lock screen will terminate the current SSO session.

- Tap Enroll User from the Lock Screen menu - When this option is selected, Identity Guardian checks for an active Microsoft session. If detected, the session is terminated, and the “On user change” lock screen event is triggered, applying the associated Verification Setup. A new SSO login screen then appears. Upon login, the self-enrollment process begins.
Note: If the user presses the back button during or after self-enrollment, the "On User Change" lock screen event remains active with its associated Verification Setup.
Guardian Safe
Guardian Safe enhances productivity and security on both shared and personally assigned devices by securely storing user credentials after a single entry on any application's login screen. It automatically populates these credentials for future logins, streamlining access for both native and web applications, such as Microsoft Edge and Google Chrome. Users can easily save credentials from any login screen and have the option to mark specific apps as “ignored” to prevent credential storage. They can also view, modify, or delete saved credentials, providing flexibility and control over their login information.
Guardian Safe is compatible with both SSO and non-SSO environments. When enabled, any app with a login screen displays the Guardian Safe floating button when a password field is detected. Tapping the password field prompts the user to save credentials for that app if they have not been saved yet. To manage their saved credentials within Guardian Safe, users must complete multifactor authentication as configured by the administrator. If Auto-Fill SSO is enabled, previously saved credentials are automatically populated into the SSO login page, eliminating the need for manual entry during authentication.
![]()
The appearance of the Guardian Safe floating button signifies that Guardian Safe is active.
Activation During Login
Guardian Safe adapts its behavior based on the structure of a website or native app's login process. The Guardian Safe floating quick access button appears at different stages depending on how fields are loaded.
| Detection Scenario | Behavior Logic | Floating Button/Prompt State |
|---|---|---|
| Background Detection (Hidden Fields) |
Many apps or sites load username and password fields simultaneously, even if the password field is initially hidden. | The button activates immediately for use upon page or app interaction. |
| Sequential Detection (Multi-Step Logins) |
The password field is absent until a "Next" button is clicked or a new page loads. | The button remains inactive until the second step is reached and the password field is present. |
| Initial Login Experience | During the first visit to a site or app, a hidden password field is detected even if not yet visible. | The "Save credentials" prompt appears immediately to prepare for capturing all login information at once. |
Requirements
- Internet access
- Identity Guardian license
Prerequisites
- ZDNA Cloud Registration - Register with Zebra.com based on the instructions provided in ZDNA Cloud Setup.
- Device Enrollment - Ensure the device is enrolled and connected to Zebra DNA Cloud.
- User Barcode - The user barcode must be generated with Identity Guardian v1.6 or later.
- Set Authentication Scheme - Choose one of the following based on the deployment model:
- Personally Assigned Devices: Configure authentication using any Primary Authentication Factor. If ANDROID_LOCK is selected, Keyguard must be set to ENABLE under Usage Mode settings.
- Shared Devices: Configure an authentication scheme that combines a barcode with a Primary Authentication Factor (such as facial biometrics or a user PIN/passcode) to secure access to stored credentials. Barcode regeneration requirements vary by upgrade path:
- Upgrades from versions prior to Identity Guardian v1.6: Barcode regeneration is required.
- Upgrades from Identity Guardian v1.6 or later: Barcode regeneration is not required.
- Enable Temporary Data Storage - Enable this option in Shared Device Authentication from Managed Configurations.
Important Notes
- Auto-Fill SSO - When Auto-Fill SSO is enabled and Guardian Safe is disabled, only SSO login credentials are visible in Guardian Safe. These are identified by the IG logo and are used solely for authentication with Identity Guardian.
- Lost Barcodes: If an Identity Guardian user loses their barcode, the stored information in Guardian Safe cannot be accessed with a newly created enrollment barcode. Consequently, new credentials (user name and password) must be saved again for all applications.
- Supported Authentication Values: Only applications with user ID and password fields are supported. Applications requiring One-Time PIN fields are not supported. Acceptable values for the user ID can vary by application and may include values such as an email address, phone number or user name.
- App Challenges: Certain apps may experience difficulties when saving or entering credentials in Guardian Safe. If you encounter such issues, please contact Zebra technical support for assistance.
- User Re-Enrollment: When a user re-enrolls with the same user ID, Identity Guardian does not recognize previously saved credentials. As a result, users are prompted to save their credentials for applications they have already used. To resolve this, users must re-enter and save their credentials again.
Enable Guardian Safe
Guardian Safe is enabled through ZDNA Cloud and the Guardian Safe Configuration in Managed Configurations. Once enabled, Accessibility Service permission must be granted to allow user credentials to be automatically populated.
To enable Guardian Safe:
- Login to Zebra DNA Cloud.
- Click the user icon at the top right corner and select My Services from the menu.

- Toggle to enable Guardian Safe.

- When creating the Managed Configurations profile, under Guardian Safe Configuration enable Append Username and Password Safe and configure the other available options as needed.
Choose one of the following methods to grant Accessibility Service permission:
- Automatically Grant Accessibility Permission - The administrator can enable the Automatically Grant Accessibilty Permission option in Guardian Safe Configuration under Managed Configurations. Once this option is enabled, the Guardian Safe Settings screen will display Use Accessibility: On/Off as grayed out, making it non-changeable by the user and no user interaction is required.
- Manually Grant Accessibility Permission - User intervention is required to accept the required permission. The user should follow these steps:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- Tap the menu icon in the top right corner and select Settings.

- Grant the Android Accessibility Service permission for Identity Guardian: - Toggle to enable Use Accessibility: On/Off.
- When the Accessibility Service Disclosure statement appears, tap Accept.
- In the Accessibility screen, tap Identity Guardian.
- Enable Use Identity Guardian.
- Tap Allow.
- Tap Back continuously until Guardian Safe is closed.
MPIN-Protected Guardian Safe
Guardian Safe securely stores credentials for supported native applications and websites on Shared Devices, protecting them alongside Personalized Device Settings (if enabled) with a Master Personal Identification Number (MPIN). The user signs in using the administrator-configured authentication method — such as Single Sign-On (SSO), Zebra DNA Cloud Passcode, NFC, or Barcode — and enters the MPIN when Guardian Safe requests access. After setup, the same protected profile remains accessible through any supported sign-in method configured for the device.
Rather than tying data to a single physical sign-in source, enabling the MPIN allows a Shared Device user to access the same protected profile across multiple devices. While the MPIN protects Guardian Safe data, it does not replace the authentication factors configured by the administrator.
Security Principles & Access Control:
- Data Encryption, Not Authentication: The MPIN functions strictly as a data-encryption mechanism to secure credentials and personalized settings. It does not replace Face recognition, Passcodes, SSO, NFC, Barcode, or any other primary login factor configured by the administrator.
- Administrative Override: The administrator-configured authentication flow retains full control over initial device sign-in and Guardian Safe entry.
- Biometric Interoperability: For NFC or Barcode workflows, Guardian Safe's Save Credentials and Auto-Fill processes may prompt for Face recognition before requesting the MPIN when Face is configured as the Primary Authentication Factor.
Profile Portability & Data Continuity:
- Cross-Method Portability: After MPIN setup or migration, a Shared Device user accesses a single, unified profile across all supported sign-in workflows. Changing the primary sign-in source does not generate a separate profile.
- Dynamic Settings Management: When enabled, Personalized Device Settings are dynamically linked to the MPIN-protected profile and applied automatically upon validation. Any modifications made to these settings are updated in real-time.
- Session Cleanup: Upon logout or user change, the device automatically restores its baseline default settings before the next session begins.
Synchronization & Offline Behavior:
- Data Synchronization: When profiles are synchronized across devices, entering the existing MPIN on another supported Shared Device grants access to synchronized Guardian Safe data and settings. Data synchronization and initial retrieval depend on network availability and the deployment configuration.
- Offline Operation: Once a MPIN-protected profile is active, cached profiles can only be unlocked offline via the validated MPIN in accordance with the deployment policy. Switching back to standalone NFC or Barcode sign-in methods will not migrate or recover the MPIN-secured Guardian Safe data. Instead, signing in without the validated MPIN initializes a completely fresh Guardian Safe profile, rendering the previous MPIN-secured data inaccessible during that session.
IMPORTANT: Unsupported Configuration: The simultaneous combination of pure SSO (where SSO is the Primary Authentication Factor, no Comparison Source is used, and no Secondary Authentication Factor is configured), enabled MPIN, and enabled Personalized Settings is not supported in this release. Support for this configuration is planned for a future release.
Admin Setup
Administrators must configure the user authentication settings and enable Guardian Safe with MPIN. These settings configured through Managed Configurations within the Enterprise Mobility Management (EMM) console or Zebra DNA Cloud.
Configure Managed Configurations:
- In Shared Device Authentication, configure the required authentication schemes, including comparison source and verification factors. Under User Verification Methods, select a setting below based on the required authentication method: SSO, Cloud Passcode, or NFC/Barcode.
- For SSO:
- Comparison Source: NONE
- Primary Authentication Factor: SSO
- For Zebra DNA Cloud Passcode:
- Comparison Source: CLOUD
- Primary Authentication Factor: CLOUD_PASSCODE
- For NFC or Barcode:
- Comparison Source: NFC or Barcode (as required)
- Primary Authentication Factor: Configure as needed.
- Secondary Authentication Factor: Configure as needed.
- For SSO:
- In Guardian Safe Configuration, ensure Guardian Safe prompts for an MPIN and utilizes Autofill for stored credentials by setting the following:
- MPIN Configuration: true
- Does Autofill require authentication: true
- Save the changes and deploy them to the devices.
Usage
For users with existing Guardian Safe data secured by an eligible NFC or Barcode source, the system automatically migrates the data during the first login after MPIN setup.
To complete the migration, start the login process using the original eligible NFC or Barcode source, complete the prompted MPIN configuration step, then allow Identity Guardian to successfully transfer and integrate the existing data into the new MPIN-protected profile. The steps are provided below.
The following workflows detail how the end-user can enroll, authenticate, and manage credentials using SSO, Zebra DNA Cloud Passcode, NFC, or Barcode with Guardian Safe and MPIN.
Migration & First-Time Setup
For environments where Guardian Safe data is accessed via an eligible NFC or Barcode source, users must perform a mandatory recovery and migration flow.
- One-Time Migration: For users with existing Guardian Safe data secured by an eligible NFC card or Barcode, the system automatically migrates the data during the first login after MPIN setup.
- Migration Interruptions: Canceling or failing the migration process keeps the existing protected data locked until the approved setup or migration flow is successfully completed.
Migration & Setup Steps:
| Step | Outcome |
| 1. Open the Identity Guardian app. Tap Unlock. |
|
| 2. Authenticate using the configured authentication method: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 3. The Enter MPIN screen appears. Tap back to send the app to the background. |
|
| 4. Re-open Identity Guardian. Tap the top-right menu and select Guardian Safe. |
|
| 5. Authenticate again using the configured authentication scheme: SSO, Cloud Passcode, or NFC/Barcode. |
SSO
Cloud Passcode |
| 6. Open the Guardian Safe menu and select Forgot MPIN. |
|
| 7. A confirmation message appears. Tap Yes. The system deletes the user's MPIN-protected Guardian Safe data. |
|
| 8. Re-uuthenticate using the configured authentication method when prompted: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 9. Enter a secure numeric passcode meeting the MPIN Requirements above, re-enter it to confirm, and tap Save. This completes the setup and automatically redirects the app to the Identity Guardian home screen. |
|
First-Time Enrollment
New users follow the MPIN enrollment process immediately after authenticating via the configured SSO, Zebra DNA Cloud Passcode, NFC, or Barcode method.
During this initial login:
- Existing Profiles: If an MPIN-protected profile already exists for the user, Identity Guardian prompts to "Enter MPIN."
- New Profiles & Migration: If no profile exists, the system prompts to "Create MPIN" or automatically initiates the approved migration flow.
MPIN Requirements: When configuring an MPIN, the passcode must meet the following criteria:
- Numeric characters only
- Length: 6 to 20 digits
Enrollment Steps:
>| Step | Outcome |
|---|---|
| 1. Open the Identity Guardian app. Tap Unlock. |
|
| 2. Authenticate using the configured authentication method: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 3. Enter a secure numeric passcode meeting the MPIN Requirements above, re-enter it to confirm, and tap Save. This completes the setup, and the app redirects to the Identity Guardian home screen. |
|
Login & Usage Flow
Daily Authentication (After Setup): Once a user has successfully completed the administrator-configured authentication (SSO, Cloud Passcode, NFC, or Barcode) and MPIN setup, the user's supported Personalized Device Settings are applied (if enabled) and subsequent logins to Guardian Safe-protected native or web apps are streamlined. Users are not required to enter the MPIN for every device login session; however, a new session prompts for MPIN validation. On logout or user change, the device automatically restores its baseline deployment defaults.
| Step | Outcome |
| 1. Open the Identity Guardian app. Tap Unlock. |
|
| 2. Authenticate using the configured authentication method: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 3. Enter the configured MPIN and tap Submit. Access is granted to Guardian Safe and all stored credentials. |
|
Credential Usage Flow: Once authenticated into Guardian Safe, users can seamlessly manage and utilize their stored credentials from external applications.
| Step | Device Screen |
| 1. Open the external application and enter the required login credentials. When prompted by Guardian Safe, choose to Save the credentials. |
|
| 2. To manage stored data, return to the Identity Guardian app and select Guardian Safe from the top-right menu. |
|
| 3. View, Edit, or Delete stored credentials as needed. |
|
MPIN Behavior and Management
Incomplete MPIN Setup: If a user bypasses MPIN setup during the initial workflow, the following restrictions apply:
- Continued Usage: The user can continue using standard Identity Guardian features.
- Restricted Features: Stored Guardian Safe credentials remain hidden, and the Autofill feature is disabled.
- Setup Prompt: During any attempt to save a new credential, the MPIN setup screen automatically appears.
Recommended Action: To restore full functionality, set an MPIN manually by navigating to the Identity Guardian menu, then select Setup MPIN. Enter a secure numeric passcode meeting the MPIN Requirements above, re-enter it to confirm, and tap Save.
|
|
Skipped MPIN Entry (During Daily Login): If a user does not enter the MPIN when prompted after the configured sign-in method:
- Stored credentials remain hidden.
- Autofill functionality is disabled.
Recommended Action: To access credentials, enter the MPIN by navigating to the Identity Guardian menu, select Enter MPIN, then enter the MPIN.
|
|
Incorrect MPIN Attempts: When three (3) consecutive incorrect MPIN entry attempts occur, Identity Guardian application automatically minimizes to the background. To recover, relaunch the application, tap the three-dot menu icon in the upper-right corner of the screen, and select Enter MPIN option to re-attempt authentication.

MPIN Reset and Recovery:
Changing an Existing MPIN: Changing the MPIN re-encrypts the user's saved credentials and supported Personalized Device Settings. If the current MPIN or the existing protected data cannot be validated, the modification process fails securely to prevent unauthorized access.
| Step | Device Screen |
| 1. Open the Identity Guardian app. Tap Unlock. |
|
| 2. Authenticate using the configured authentication method: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 3. Open the Guardian Safe menu and select Change MPIN. |
|
| 4. Enter the current MPIN, new MPIN, re-enter the new MPIN, then tap Save. All stored data is securely re-encrypted using the new MPIN. |
|
Forgot MPIN: If an MPIN is forgotten, it cannot be recovered. To regain access, the user must reset the MPIN, which deletes all Identity Guardian stored data (both locally on the device and in the cloud).
An MPIN cannot be recovered. Initiating the "Forgot MPIN" process performs a clean-slate reset, which permanently deletes the MPIN, saved Guardian Safe credentials, and all MPIN-protected Personalized Device Settings. This reset process cannot restore older NFC- or Barcode-secured database copies and cannot be undone.
| Step | Device Screen |
| 1. Open the Identity Guardian app. Tap Unlock. |
|
| 2. Authenticate using the configured authentication method: SSO, Cloud Passcode, NFC, or Barcode. |
SSO
Cloud Passcode |
| 3. Tap the top-right menu and select Guardian Safe. |
|
| 4. Open the Guardian Safe menu and select Forgot MPIN. |
|
| 5. A confirmation message appears. Tap Yes. The system deletes the user's MPIN-protected Guardian Safe data. |
|
| 6. Re-authenticate when prompted. |
SSO
Cloud Passcode |
| 7. Enter a secure numeric passcode meeting the MPIN Requirements above, re-enter it to confirm, and tap Save. |
|
Save Credentials
To save user app login credentials:
- Open an app with a login screen (containing a user ID and password field)
- Tap the password field.

- A prompt appears asking if the user would like to save their credentials. Tap Yes.
- If No is selected, the user credentials are not saved (requiring the user to manually enter their credentials each time they log in to the app), and the app is added to the Ignored Apps list.

- If No is selected, the user credentials are not saved (requiring the user to manually enter their credentials each time they log in to the app), and the app is added to the Ignored Apps list.
- The Guardian Safe input screen appears. Enter the user credentials, then tap Save Credentials.
Note: The user may need to scroll up to see the username and password fields.
- The user login credentials are now saved and will automatically populate in future login attempts when tapping the user name or password field.
Auto-Populate Credentials
After an application's login credentials are saved, subsequent login attempts will automatically populate the credentials in the login screen.
Delay in Auto-Populating Credentials After Reboot: After a device reboot, users may encounter a delay in the automatic population of their credentials during the first login attempt.
- Open an app where the login credentials have previously been saved.

- Tap the user name or password field on the login screen. The user is prompted to authenticate via facial biometric scan or passcode entry.
- Upon successful authentication, the login credentials are automatically populated in the respective fields.

- Tap the sign-in button to access the app.
View Apps
To view apps with login credentials saved in Guardian Safe:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- In the Saved Credentials tab, a list of apps with saved passwords is displayed with their corresponding logo. Tap the eye icon to reveal the password. If Auto-Fill SSO is enabled, the SSO login is saved with the IG logo, indicating that they are SSO credentials meant solely for use with Identity Guardian.
![]() |
![]() |
|
| Saved app credentials | Saved SSO credentials |
Ignored Apps
Prevent Guardian Safe from saving login credentials from specific apps by designating them as Ignored Apps:
- Open an app in the login screen.

- When prompted to save the user credentials during login, tap No.

- The user is directed back to the login screen and the login credentials are not saved. The app is listed in the Ignored Apps tab with the toggle button disabled.

Future login attempts in this app will no longer trigger Guardian Safe to offer saving the login credentials and the Guardian Safe floating quick access button is no longer present.
To view all Ignored Apps:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- Tap the Ignored Apps tab. A list of ignored apps is displayed.

To save credentials from an Ignored App:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- Tap the Ignored Apps tab. A list of ignored apps is displayed.

- Tap on the app to save credentials and tap Yes in the confirmation message.

- The app is removed from the Ignored Apps tab. The user is prompted to save credentials the next time the app is opened.

Edit Credentials
There are two methods to modify an app's login credentials saved within Guardian Safe:
- Using Guardian Safe's floating quick access button on the app's login screen
- Through Guardian Safe directly with Identity Guardian
Floating Quick Access Button: To edit the login credentials for an app using the Guardian Safe floating quick access button:
- In the app's login screen, tap on the Guardian Safe floating quick access icon.

- Guardian Safe appears, allowing for the user name or password to be changed. Make the desired changes and tap Save Credentials.

- The updated credentials are now saved.
- Future login attempts in the app will automatically be populated with the updated login credentials.
Guardian Safe: To edit the login credentials for an app through Guardian Safe:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- In the Saved Credentials tab, find the app to modify. Tap its hamburger menu on the right and select Edit.

- Edit the user name and/or password.
- Tap Save Credentials.

- Future login attempts in the app will automatically be populated with the updated login credentials.
Delete Credentials
To delete app login credentials saved in Guardian Safe:
- Open Identity Guardian.

- Tap the menu icon in the top right corner and select Guardian Safe.

- Choose one of the following actions based on the administrator's configurations:
- Scan the user barcode, and then perform the designated authentication methods.
- Tap the NFC card on the device, and then perform the designated authentication methods.
- The apps with passwords saved are listed. In the Saved Credentials tab, find the app to modify the credentials. Tap its hamburger menu on the right and select Delete.

- Tap Yes in the confirmation message.

- The app is removed from the list.

Delete Users
Users can be removed from the Device Users section in ZDNA Cloud. When a user is deleted, all saved application credentials and the user enrollment barcode are removed. To regain access, The barcode must be regenerated for the same user.
Device Alarm
The Device Alarm is an audible alert activated when a user is not logged into the device or it is not returned to the powered cradle within the specified timeout period. These conditions can be configured and managed by the administrator via Managed Configurations. This feature is designed to prevent devices from remaining idle in unauthorized locations and to ensure they are returned to their cradle after use.
Admin Setup
Configure Managed Configurations:
- Lock Screen Configuration:
- Under Audio Configuration, toggle to activate Alarm for Login Timeout and select ENABLE.
- Enter the Alarm Timeout duration in seconds. Accepted range: 60 to 600.
- Save the changes.
Usage
The alarm is activated when a device is removed from its cradle and the user does not log in before the specified countdown ends, or when a user logs out and does not return the device to a powered cradle or log back in within the specified timeout period. The alarm sounds continuously until it is deactivated. This applies even a voice call is accepted while a user is not signed in - the alarm will continue to ring.
Once activated, the alarm continually plays and only deactivates when a user logs into the device or places the device back on the powered cradle.
If a user logs in and locks the device without logging out, the alarm will not be activated.
Note: The alarm will not activate if the device is in Doze mode due to restrictions in this mode.
![]() |
![]() |
![]() |
![]() |
|||
| Alarm countdown triggered | Notification of alarm countdown | Alarm activated | Notification of alarm activated |
Quick Access (Apps)
Quick Access enables devices users to launch approved utility applications directly from the lock screen without authentication. By eliminating sign-in requirements for basic tools such as calculators or pairing utilities, operational efficiency increases while device security remains intact. Quick Access operates within an unauthenticated workspace launcher screen while the device remains locked.
This feature is supported in the following scenarios:
- Shared Devices: Accessible on the lock screen only when signed out (i.e., not accessible when the device is locked during an active sign-in session).
- Personally Assigned Devices: Accessible on the lock screen at all times.
System Behaviors:
- Real-Time Revocation: When an administrator revokes application access via EMM, the application icon is immediately removed from the Quick Access launcher on the device.
- Uninstalled Application Handling: Configured applications not yet present on the device display a greyed-out icon. Tapping the icon displays a toast notification: "App is not installed."
- Authentication Intercept: If an operator taps a valid NFC card or scans an Identity Guardian barcode while in the Quick Access launcher, a prompt appears asking if the user would like to log in. (Other barcode formats are ignored.)
- Dynamic Install/Uninstall Synchronization: Applications installed or removed during an active launcher session update their launch state upon returning to the lock screen and relaunching Quick Access.
Admin Setup
Administrators configure Quick Access through EMM Managed Configurations to designated applications accessible from the lock screen.
EMM Managed Configuration Steps:
Under Lock Screen Configuration, click Add Application Details to configure a target application.
For each app permitted on the lock screen, configure the following parameters:
- Package Name: [Enter the package name of the app, e.g.,
com.google.android.calculator] - Activity Name: [Specify the activity name, use the wildcard
*to allow any activity.] - Add to Quick Access: true
IMPORTANT:Do not add the DataWedge application to Quick Access when Identity Guardian operates in Shared Device Mode. Doing so causes the device to display an endless "Initialization... please wait..." message until a manual hardware reboot occurs.- Package Name: [Enter the package name of the app, e.g.,
Save and deploy the configuration to the devices.
Key Configuration & Operational Considerations
- Device-Specific Package & Activity Mapping: Application package names or primary activity identifiers can vary for certain applications (e.g., Bluetooth Pairing Utility) depending on the device hardware model.
- Resolution: Administrators must map the precise package and activity name corresponding to each specific device model. For example, for the Bluetooth Pairing Utility pre-installed on Zebra mobile computers:
Application Device Model Package Name Activity Name Bluetooth Pairing Utility ET40 com.symbol.scanning.scanningframeworkcom.symbol.btapp.BTActivityBluetooth Pairing Utility TC22 com.symbol.datawedgecom.symbol.btapp.BTActivity
- Resolution: Administrators must map the precise package and activity name corresponding to each specific device model. For example, for the Bluetooth Pairing Utility pre-installed on Zebra mobile computers:
- Secondary Activity Dependencies and Runtime Permissions: Certain applications fail to launch or function correctly if child activities (such as runtime permission dialogs or internal home activities) are not explicitly allowed. These auxiliary activities must be configured to prevent Identity Guardian from intercepting the workflow.
- Sample Secondary Home Screen Requirement:
- Input Target:
com.zebra.licensemgrservice/.ui.launch.LaunchActivity - Required Allowed Activity:
com.zebra.licensemgrservice/.ui.home.HomeActivity
- Input Target:
- Sample Runtime Permission Dialogs:
- Input Target:
com.google.android.youtube/* - Required Allowed Activity:
com.google.android.permissioncontroller/com.android.permissioncontroller.permission.ui.GrantPermissionsActivity(Enables operators to grant runtime permissions without Identity Guardian blocking the permission prompt).
- Input Target:
- Sample Secondary Home Screen Requirement:
- Back-Press Navigation on Non-Standard Applications: Certain applications (such as Gmail) do not adhere to standard Android back-press navigation events.
- Operational Flow: Pressing the Back button within these applications directs the operator directly to the Identity Guardian lock screen rather than the Quick Access launcher interface.
- StageNow Activity Configuration: The Quick Access launcher requires explicit activity endpoints and cannot resolve wildcard (
*) entries for primary menu display. Configuring StageNow requires a two-part setup: registering the specific entry point for launcher display, and adding a secondary wildcard rule for background execution.- Step 1: Register the Primary StageNow Interface - Define the explicit entry point to display StageNow in the Quick Access launcher:
Parameter Value Package Name com.zebra.devicemanagerActivity Name com.zebra.devicemanager.stagenow.main.HomeScreenAdd to Quick Access true - Step 2: Permit Secondary StageNow Activities - Create a secondary entry to allow auxiliary StageNow sub-activities to execute without adding unnecessary icons to the launcher interface:
Parameter Value Package Name com.zebra.devicemanagerActivity Name *Add to Quick Access false
- Step 1: Register the Primary StageNow Interface - Define the explicit entry point to display StageNow in the Quick Access launcher:
- Overlay Suppression on Privileged System Interfaces: The floating Exit View button overlay may disappear when accessing privileged system screens or secure system dialogs (e.g., the Files / Documents UI,
com.android.documentsui) due to built-in Android OS security controls.- Recovery: Pressing the device Back button exits the privileged interface and immediately restores the Exit View overlay button.
- Application State and Cache on Exit: In certain applications (e.g., Calculator), transient session data is cleared when exiting via the Back button, but preserved when exiting via the Exit View overlay button.
- Cause: The Back button triggers standard app closure and memory cleanup, whereas Exit View sends the application to the background without closing it.
Usage
Quick Access provides direct access to authorized utility applications without authentication into Identity Guardian.
- On the Identity Guardian lock screen, open the Quick Access icon located in the lower-left corner.

- The launcher displays approved applications along with an Exit View overlay button. This button can be dragged to any location on the screen to prevent obstruction.

- Tap the icon of the desired application to launch. The Exit View button remains accessible over the active app.

- Tap Exit View at any time to terminate the session and return to the main lock screen. On Shared Devices, this action also clears the cached data of any applications opened during the Quick Access session.
- To authenticate directly from the launcher, scan a user barcode or tap an NFC card. A confirmation message appears to proceed with sign-in.

NOTE: Disabled applications cannot be opened from the launcher; selecting a disabled application displays a message stating that the app is disabled. Similarly, attempting to open an uninstalled application displays an alert that the app is not installed.
External Display
Identity Guardian can detect when a device is connected to a Workstation Connect (WSC) dock with an external display. This functionality enables the system to block automatic check-ins while the device remains fully operational with the external display, providing a seamless and uninterrupted user experience.
Note: This feature is designed to work in WSC Mirror Mode only. Desktop Mode is not supported.
Admin Setup
Configure the following Managed Configurations:
- Lock Screen Configuration: Under External Display Support:
- Prevent Logout: Enable
- Maximum Delay Time: [Specify the delay duration (in seconds) for the notification message, allowing adequate time for the external display to be detected. Range: 5 to 10 seconds.]
Usage
The following steps outline the system's behavior based on the external display configuration, dock type, and connection to an external display.
Dock the Device: Place the device on either an AC dock or a Workstation Connect (WSC) dock, with or without an external display.
Identity Guardian Evaluation: Identity Guardian assesses the configuration to determine the appropriate action:
- If the device is placed on a WSC dock without an external display connected: Identity Guardian proceeds to check-in the user.
- If "Prevent Logout" is enabled: A delay timer, configurable between 5 to 10 seconds, is initiated. During this delay, a notification message informs the user that the WSC dock and external display are being detected. The system checks the HDMI status every second during this delay:
- If HDMI is detected: Automatic check-in is blocked.
- If HDMI is not detected: Automatic check-in proceeds after the delay period.
- If "Prevent Logout" is disabled: Check-in proceeds immediately, regardless of the dock type or HDMI status.
Note: The default delay of 5 seconds may not be sufficient for some devices to detect an external display connection, as detection time may vary depending on the device. Zebra recommends testing the configuration and increasing the delay value if necessary to ensure proper functionality.
Message displayed during the delay
Personalized Device Settings
The Personalized Device Settings feature grants access to specified Android system settings so individual users can tailor device preferences for their specific needs. This ensures a productive and personalized workflow on devices during an authenticated session.
Personalized settings are restricted to a single barcode per user profile. If a user is associated with multiple barcodes, scanning a new barcode causes the device to restore its default system settings.
Users can modify and personalize the following categories of device settings:
- Language Settings: Changes the system language setting across the operating system and all supported applications.
- Font and Display Settings: Controls text font size, screen display size, screen brightness, and device theme mode.
- Touch and Haptics Settings: Adjusts touch responsiveness for a long press and manages vibration for haptic feedback.
- Sound Settings: Controls the audio output volume level.
- Accessibility Settings: Adjusts assistive technologies to aid with diverse physical or cognitive needs, such as Talk Back, Text to Speech (converts text to audio voice), color contrast, and magnification.
Note: These settings apply dynamically to the authenticated user's active session and revert or clear based on the sign-out and session persistence configurations defined by the administrator.
Requirements
The following conditions must be satisfied:
| Requirement | Required State |
|---|---|
| License | A valid Identity Guardian license is present on the device. |
| Managed Configuration | • Under Usage Mode, set Application Mode to AUTHENTICATION. • Under Guardian Safe Configuration, set Enable Personalization Configuration to true. |
| Login Type | The user logs in using Barcode or NFC Authentication. |
Feature Limitations and Exclusions: Personalized Device Settings are not available under any of the following login scenarios:
- Legacy Barcode login
- Admin Bypass login
- SSO (Single Sign-On) login
- Cloud Passcode login
Admin Setup
To allow users to access Personalized Device Settings, an administrator must first enable the feature at the account level within the Zebra DNA Cloud console.
Steps to Enable Personalized Device Settings:
- Log in to the Zebra DNA Cloud.
- Navigate to My Services in the left-hand menu.
- Locate the Personalized Device Settings/Guardian Safe option and toggle to enable this setting.

Managed Configurations
Once enabled in the Zebra DNA Cloud, the feature requires further configuration via Managed Configurations. These parameters are located under the Guardian Safe Configuration section of the schema. Toggle to enable the settings as needed:
- Personalization Configuration
- Enable Personalization Configuration
- Language Settings
- Font and Display Settings
- Touch and Haptics Settings
- Sound Settings
- Accessibility Settings
Usage
To access the Personalized Device Settings and customize the device interface during an active session, follow these steps:
- After successful user authentication, personalized device settings are applied automatically from local storage or the Zebra DNA Cloud. Launch the Identity Guardian application.

- Tap the menu (three vertical dots) at the top-right of the screen, and select Personalized Settings.

- The Personalized Device Settings screen opens, displaying setting categories enabled by the administrator in the Managed Configuration schema.

- After user sign-out, the device automatically resets to its original state, restoring the default configurations for the next user.
Offline Behavior
The Personalized Device Settings feature remains functional even when the device does not have an active network connection. The system is designed to queue updates locally to ensure a seamless experience.
Below is the operational behavior of the feature during and after offline states:
| Action/Event | Offline Behavior & Expected System Actions |
|---|---|
| Saving Settings | All setting adjustments are saved locally on the device immediately, allowing offline customization. |
| Cloud Synchronization | The cloud synchronization step is skipped. A toast message appears on the screen to notify the user: "User preferences returned to default. No internet." |
| Network Reconnection | Cloud synchronization automatically pauses and schedules a background retry for when network connectivity returns. Under stable network conditions, synchronization takes approximately 10 seconds to complete and apply personalized device settings. |
| Applying Saved Settings | Once the network connection is re-established, the locally saved settings are synced with the cloud and applied: • If the app is in the foreground, a toast message displays: "User preferences reapplied. Internet is connected" • If the app is in the background, a system tray notification displays: "User preferences reapplied. Internet is connected" |
Language
Set the preferred system and display language.
To change the language:
- From the settings screen, tap Language.


- Tap the Language Selector option to open the full language list. Select the desired language. Currently, English and French are the only supported languages in Identity Guardian. Tap Save to apply the setting.

- The language screen displays the chosen language. Tap Save to apply the setting.

Font & Display
Font & Display settings control text size, icon size, screen brightness, and the user interface theme.
![]() |
![]() |
Select Font & Display from the settings screen
Font & Display Size: Controls the scaling of on-screen text and launcher elements:
- Font Size: Use the Font Size slider to increase or decrease the system text size. The active percentage value is displayed next to the slider. The default value aligns with the current system setting.
- Display Size: Use the Display Size dropdown to adjust the overall scaling of on-screen elements like icons, buttons, and menus. Available options depend on the device type: - Phone/Handheld Options: Small, Default, Large. - Tablet-Specific Options: Small, Default, Large, Larger, Largest.
Tap Save to store and apply your text and scaling preferences.

Display: Controls screen brightness levels and manages the system-wide Light/Dark theme.
- Screen Brightness: Adjust the Display Brightness slider to the preferred level (0%–100%). The current percentage is displayed next to the slider. Visual brightness changes take effect starting at 10%:
- 0% – 10%: The physical backlight output is locked at a minimum threshold of 10%. Dropping the slider below 11% triggers a Backlight Off (Screen Blackout/Deep Sleep) state on the device.
- 11% – 100%: Standard linear backlight dimming range.
- Theme Mode: Select Dark Mode or Light Mode using the toggles. The default value depends on the Android system theme. - Dark Mode: Applies a high-contrast dark background with light text to reduce eye strain in low-light environments. - Light Mode: Applies a white background optimized for high-visibility bright environments.
Tap Save to apply the brightness and theme selections.

Touch & Haptics
Touch & Haptics settings manage system-level physical feedback and touch-and-hold delays. The default values depend on the Android system settings.
![]() |
![]() |
Select Touch & Haptics from the settings screen
Touch-and-Hold Duration: Adjusts the duration the finger must remain on the screen before a tap is registered as a "long press". Choose between Short, Medium, or Long delay times.
Haptic Feedback: Enable or Disable physical vibration feedback when tapping interactive elements. Haptic feedback is highly recommended for sensory confirmation in noisy enterprise environments (such as warehouses or field service areas).
Tap Save to apply and store the preferences.
Sound
Sound settings set the preferred media volume.
![]() |
![]() |
Select Sound from the settings screen
Use the volume slider to set the preferred audio output level (0%–100%). The active percentage value is displayed next to the slider. The initial slider value is synchronized with the existing Android system volume settings. Tap Save to apply the setting.
Accessibility
Accessibility settings configure assistive technologies. Feature availability depends on the Android version and the default values align with existing Android system settings.
![]() |
![]() |
![]() |
Select Accessibility from the settings screen to display the Accessibility settings
Accessibility Settings: Toggle to enable the desired setting(s).
- Talk Back: A screen reader that speaks screen content aloud. Requires Android 13 or above; this option is grayed out on older Android versions.
- Text to Speech: Allows user to tap any item on screen to hear it read aloud. Requires Android 13 or above; this option is grayed out on older Android versions.
- Live Caption: Automatically captions speech from any media playing on the device. Availability is device hardware-dependent.
Color and Contrast Settings: Toggle to enable the desired setting(s).
- Color Correction: Adjusts colors for users with color vision deficiencies.
- Color Inversion: Inverts screen colors for improved visibility.
- High Contrast Text: Makes text easier to read by sharpening its edges.
Magnification: Enable/disable a zoom function to enlarge parts of the screen.
Tap Save to apply the setting selections.
ZDNA Cloud
Identity Guardian integrates with the Zebra DNA (ZDNA) Cloud platform to provide administrators with centralized visibility and management of user activity on devices. From the ZDNA Cloud console, key administrative tasks include:
- Tracking which users are signed in or out of devices
- Monitoring security measures
- Managing user access by expiring accounts, resetting PIN passcodes, and overriding screen locks
- Viewing user login history with usage times
For a complete guide to all management features, refer to the Device Users section in the Zebra DNA Cloud documentation.

The Device Users option in the left menu of the ZDNA Cloud is dynamically displayed based on the presence of enrolled users in Identity Guardian.
- If no users are enrolled in Identity Guardian or if the administrator manually deletes all users, the Device Users menu option becomes hidden and inaccessible in ZDNA Cloud.
- When users are re-enrolled in Identity Guardian (e.g., through a device or user re-enrollment process), the Device Users menu option automatically becomes visible in ZDNA Cloud.
This dynamic behavior ensures the Device Users option appears only when active users are present, enhancing the interface's relevance and usability for administrators.
For more information, see the ZDNA Cloud documentation and for updates relevant to Identity Guardian within ZDNA Cloud, see the ZDNA New in... section.
Device Orientation
This section provides device orientation guidelines for both mobile and tablet devices.
Mobile Devices
On mobile devices, only portrait mode is supported. If auto-rotation is enabled, facial biometrics is not supported in landscape mode.
Tablet/Kiosk Devices
On tablet/kiosk devices, both portrait and landscape modes are supported with auto-rotation. However, facial biometrics is not supported in landscape mode.
Notification Behavior
Identity Guardian notifications differ significantly between Android versions prior to 14 and versions 14 and above, due to changes in the Android platform.
Android Versions Prior to 14
In Android versions prior to 14, users cannot dismiss notifications triggered by the Identity Guardian app.
Android Versions 14 and Higher
Android 14 introduces updates to notification behavior, enabling users to manually dismiss Identity Guardian notifications from the device's notification drawer.
- Users can swipe to remove Identity Guardian notifications from the Android notification drawer.
- Users can dismiss both foreground and background notifications.


OR 























