Introduction
The Reauthentication Workflow allows Tenant Admins to enforce additional authentication during an active Windows session for applications integrated with Epic EHR. This ensures that user identity is re-verified before performing sensitive actions or continuing access.
Prerequisites
You must have access to Tenant Admin account.
The Windows Login application must be created in the Tenant Admin Portal, for more information refer: How to create and configure Application Type - Passwordless
Steps to Configure Re-authentication Workflow
Log in to the Tenant Admin Portal.
On the Applications page, select the preferred Windows Login application.
The application details page is displayed.
Click Configure tab > Epic EHR .
The Epic EHR page is displayed.
Do the following:
Enable Reauthentication Workflow
Configure Two User Authentication
ReAuthentication Current User (Second Factor)
Click Save.
The Reauthentication workflow is successfully configured.
Enable Reauthentication Workflow
Turn on Enable Reauthentication Workflow toggle button.
Configure one of the available reauthentication modes:
βApplication Factors: Uses authentication factors assigned at application level.
βFirst Factor Only: only reauthenticates using the first authentication factor configured.
βSecond Factor Only: only reauthenticates using the second authentication factor configured.Click Save.
Reauthenticate Current User: Reauthenticates the currently logged-in Windows user using the configured authentication device.
Do the following:
Select Reauthenticate Current User.
From the Application Factor dropdown, choose the authentication factor assigned at the application level.
Click Save.
Configure Two User Authentication
Under Mode for 1st user, select the authentication factor from dropdown.
Under Mode for 2nd user, select the authentication factor from dropdown.
Click Save.
Reauthenticate Current User - Second Factor
Select Reauthenticate Current User - Second Factor.
From the Application Factor dropdown, choose the authentication factor assigned at the application level:
OLOID is Used as Primary and Secondary Auth Device
OLOID is Used as Primary Authentication Device
OLOID is Used as Secondary Authentication Device
Click Save.
Configure Factors
Configure the appropriate Primary and Secondary factors for second-factor reauthentication through Oloid.
To configure factors, do the following:
Under Select Primary Factor, select the authentication factor from dropdown.
Under Select Secondary Factor, select the authentication factor from dropdown.
Click Save.
Note: When both options are enabled, ensure that the Primary and Secondary factors must be different.
Reauthentication workflow successfully configured.
Keywords
| Configure reauthentication workflow| Windows reauthentication Epic EHR | Reauthenticate current user Windows| Epic EHR reauthentication configuration |








