Before a token can log a user on, a Credential Linker binds the user’s Windows credentials to it: LinkNFCCard for NFC cards and phones, LinkMEMStick for USB sticks, LinkTOTP for authenticator apps, LinkX509 for certificates and Link2FA/LinkNFC2AD for second factors. The encrypted result is stored on the PC, on a share or in Active Directory.
How linking works
Each Credential Linker asks for the Windows user name, the domain (or the PC name for local accounts) and the password, and reads the token (card serial, stick, certificate or authenticator). It then stores the credentials encrypted as a soft token. At the logon screen the token unlocks the soft token and the credential provider passes the credentials to Windows.
Pick the linker by what you want the user to present:
| Scenario | Linker |
|---|---|
| Tap an NFC card or NFC phone to log on (passwordless, 2FA or 3FA) | LinkNFCCard |
| Password plus card or TOTP as second factor; card + TOTP + password for 3FA | Link2FA |
| Card as second factor stored centrally in Active Directory | LinkNFC2AD |
| Type a one-time code instead of the password | LinkTOTP |
| Certificate in the local store or on a PKI smartcard | LinkX509 |
| Plain USB memory stick as a key | LinkMEMStick |
In Edition 1 the same tools are in the tray menu. All card enrolments can also be scripted with the CodeB Admin CLI.
Where token data is stored
- On the PC (default): in the data folder
C:\ProgramData\CodeB\(subfolders such astotp,2FA,CodeBSerialCredentials,CodeBX509Credentials,CodeBBluetooth). Change it with the registry valueDataFolder. - On a file share: set
RemoteDataFolderto a UNC path. Simple, no AD changes; permissions live on the share. - In Active Directory: tick Store Data in AD in
LinkNFCCard(or useCodeBAdminCLI /add2ad). The data travels with the user object, so one admin PC can enrol cards for the whole company.
Both central options behave the same at logon, and you can switch later without reissuing cards. For tokens that must work on several PCs, install every PC with the shared certificates (/cert).
Storing in AD needs one attribute permission: altSecurityIdentities on the user objects must be readable and writable by Domain Computers (that is, LocalSystem on the joined PCs), ideally also by the user for their own object. LinkNFCCard confirms a successful write and warns if the permission is missing.
Link2FA — second and third factor
Link2FA.exe associates a user’s credentials with an NFC token or a TOTP authenticator. Either can be used alone as the second factor next to the password. If both are linked, both are required: NFC token plus TOTP code plus password — three-factor authentication.
LinkTOTP — one-time code instead of the password
LinkTOTP.exe (window “Link TOTP to User”) replaces user name and password with a TOTP one-time password. Users can keep a long, complex Windows password they never type and log on with the code from their authenticator app.
- Enter the TOTP Key and add the same key to the user’s authenticator app. Choose TOTP Digits and TOTP Algorithm to match the app.
- Enter user name, optional domain and password (twice).
- Optional: an Optional Secret that must be typed together with the code, and Store Data in AD.
- Click Link TOTP.
Most TOTP apps support only 6 digits with SHA-1. For other code lengths or stronger hash algorithms, use the CodeB Authenticator. The PC clock must be correct — see TOTP codes rejected.
LinkNFCCard — NFC cards and NFC phones
LinkNFCCard.exe links NFC cards — and Android phones with NFC running the CodeB Authenticator — as a second or third factor, or for passwordless “tap to logon”.
- Start
LinkNFCCard.exe(window “NFC Token”), select the Card Reader and place the card on it. The Card Serial (UID) appears. - Enter Username, Optional Domain and the Password twice. Validate checks the credentials first.
- Enter a Logon PIN (twice) for card + PIN logon, or leave it empty for card-only logon. An empty PIN stores the default PIN (
0000, seeDefaultSerialPIN). - Choose the Action on card removal (lock or log off) and, if you like, a Comment.
- Options: Store Data in AD stores the soft token in Active Directory; Link Card as 2nd Factor in AD requires the card next to the password; a configured Bluetooth device can be used as an extra factor or as the trigger for the removal action.
- Click Link Card.
For help designing a tap-to-logon rollout, write to info@codeb.io.
LinkNFC2AD — card as second factor in Active Directory
LinkNFC2AD.exe writes a card serial to the user’s AD object as a second factor. The command-line equivalent is CodeBAdminCLI.exe /add2fa.
LinkX509 — certificates and PKI smartcards
LinkX509.exe associates user name and password with an X.509 certificate from the local certificate store or — the best option — on a PKI smartcard. Select the certificate in the list, enter the Windows credentials (and an optional secret) and click Link Certificate.
LinkMemStick — USB memory stick as a key
LinkMEMStick.exe turns a standard USB memory stick into a logon token. Insert the stick, enter the Windows credentials and link. Plain memory sticks are ideal for evaluation; for production use NFC cards or smartcards.
Card removal: lock or log off
For card, USB-stick and Bluetooth tokens, Windows can react when the token is taken away. The action is chosen when the token is linked (CLI parameter /action) and can be enforced for everybody with the registry values LogoffAction. The stricter of the two wins.
| Value | Action on removal |
|---|---|
0 | Nothing (default). |
1 | Lock the screen. In a Remote Desktop session the session is disconnected. |
2 | Log the user off. |
The CodeB service starts the tray application in the user’s session to watch the token. Actions are recorded in the Windows Application event log under the source CodeB Credential Provider V2.
Logging on
At the logon or lock screen, select the CodeB tile (for a user that is not listed, the extra “Other User” tile). Depending on the settings, the tile shows these fields:
- Username — hidden when the tile already belongs to a known user.
- Optional Secret or Password — the Windows password, or the optional secret of a token.
- TOTP or PIN — the one-time code or the card PIN.
- Display typed values — shows what was typed.
Then present the token: tap the NFC card, insert the USB stick or smartcard, or type the TOTP code. A card linked with the default PIN logs on with the tap alone. Field labels, visibility and the focused field can be changed in the registry.
If the domain controller cannot be reached (laptop offline), Windows logs on with its cached credentials as usual. CodeB notices that the domain is unreachable and skips its AD lookups, so the offline logon is not delayed.
Keywords in the password or PIN field
Typing one of these words into Optional Secret or Password or TOTP or PIN on the logon tile opens a helper directly from the logon screen:
| Type | Opens |
|---|---|
nfc | The NFC card linking dialog. |
2fa | Link2FA (path from 2FAPath). |
changepwd | The change-password dialog. |
time | A dialog to check and set the date and time (useful when TOTP codes fail because of a wrong clock). |
In locked-down environments disable the keywords with DoNotAllowMagicWords = 1.
When a Windows password changes
A soft token holds the password that was valid when the token was linked. After a password change, token logon fails until the token is updated:
- Link the token again with the same linker, or
- for tokens in Active Directory, change the password with
CodeBAdminCLI.exe /changepw, which sets the new AD password and updates the stored soft token in the same call (example).
Frequently asked questions
Can one user have several tokens?
Yes. A typical setup is an NFC card plus a TOTP app as a backup. A user can also have several cards, and many cards can be linked to one shared Windows account (shift work).
What happens when the Windows password changes?
The soft token still holds the old password, so token logon fails until it is updated. Link the token again, or — for tokens stored in Active Directory — change the password with CodeBAdminCLI.exe /changepw, which updates AD password and soft token in one step.
Which TOTP apps work?
Any RFC 6238 app such as Microsoft Authenticator, Google Authenticator or the CodeB Authenticator. Most apps only support 6 digits with SHA-1; for other lengths or stronger hashes use the CodeB Authenticator.
What does 'Link Card as 2nd Factor in AD' change?
The card serial is written to the user’s altSecurityIdentities attribute. The card is then required in addition to the password — on every PC that reads AD — instead of replacing the password.