What’s new in MyID MFA & PSM v5.5: Your FIDO key just became your session anchor
Most security teams have a gap between the moment a user walks away from their desk and the moment the screen locks. Thirty seconds, sometimes more. It is enough time for someone to sit down at an unlocked machine and act as that user. The latest release of MyID® MFA & PSM closes that gap and tidies up several other parts of daily administration along the way.
Released on 27 May 2026, version 5.5 continues the work of moving everyday administration into the browser and broadens the range of hardware tokens the platform supports. Here is what changed and why it matters.
The FIDO key becomes a physical-presence control
Two new features in the Windows Desktop Agent work together. Auto-locking keeps a user’s account unlocked only while their registered FIDO key stays inserted. Pull the key out, and the workstation locks immediately. Auto-selection handles the other end of the session: insert a registered key and logon starts automatically, with the device and username already chosen and ready to authenticate.
Put them side by side and the key does something simple and powerful. Insert to log in, remove to lock. No PIN dance at the screen, no manual lock when stepping away, no thirty-second window for someone else to act as the user. For shared clinical workstations, trading floors and any environment where people move between machines all day, that physical link between key and session is worth more than another policy reminder.
The release also adds support for the IDEMIA One Key Bolt FIDO token, widening the range of certified, hardware-backed passkey devices that work with MyID MFA. The logon experience is the same as other supported FIDO devices. The choice of token stays with the organisation.
Administration moves into the browser
Version 5.5 delivers the second phase of retiring the legacy Microsoft Management Console snap-in. Application Management, Access Control Policies and Identity Provider configuration all move into the Web Management Portal, so administrators run everyday tasks from a single browser-based home. Phase three is on the roadmap.
Alongside that, a native policy mechanism inside the portal removes the dependence on Microsoft Group Policy for client configuration. Administrators define and distribute MyID MFA and PSM policies directly from the portal. That matters in mixed environments, and it reaches users on machines that sit outside an Active Directory domain, which Group Policy never could.
OneSpan OTP tokens come under management
Organisations standardised on OneSpan one-time password tokens can now bring that estate under MyID MFA without changing hardware. DPX seed files import directly, individual tokens are assigned to users through a new device assignment mechanism, and the resulting one-time password codes work for both Identity Provider authentication and Windows Desktop logon.
Two smaller changes worth knowing
The .NET prerequisites for the Windows Desktop Agent, the Domain Controller Agent and the MyID Authentication Server are no longer bundled with the installers. Administrators download the current packages directly from Microsoft, so systems pick up the newest security updates straight away rather than waiting for a bundled version to refresh.
Licence administration has also been refined to give clearer visibility of consumed and available licences across the platform. Reporting is simpler, scaling carries less risk of mismatch, and audits go faster.
MyID MFA sits in the middle of the authentication spectrum, modern phishing-resistant MFA for the part of the workforce that needs it, alongside password security and government-grade PKI for the rest. Version 5.5 makes that middle ground easier to run and tighter to control.
To see auto-locking and the rest of v5.5 in your own environment, book a MyID demo.
Trusted by Governments and Enterprises Worldwide
Where protecting systems and information really matters, you
will find Intercede. Whether its citizen
data, aerospace and defence systems, high-value financial transactions,
intellectual property or air traffic control, we are proud that many leading
organisations around the world choose Intercede solutions to protect themselves
against data breach, comply with regulations and ensure business continuity.
