Troubleshoot local authentication factors on ChromeOS

Identify whether recent changes to your security policies are causing authentication issues for users.

For administrators who manage ChromeOS devices for a business or school.

If users in your organization are experiencing local authentication difficulties, use the following scenarios to identify whether changes in your organization's security policies are the root cause.

As an admin, you configure local authentication factors using Local auth settings in the Google Admin console:

  1. Sign in with an administrator account to the Google Admin console.

    If you aren’t using an administrator account, you can’t access the Admin console.

  2. Go to  Menu and then Devices > Chrome > Settings. The User & browser settings page opens by default.

    Requires having the Mobile Device Management administrator privilege.

    If you signed up for Chrome Enterprise Core, go to Menu and then Chrome browser > Settings.

  3. (Optional) To apply the setting only to some users and enrolled browsers, at the side, select an organizational unit (often used for departments) or configuration group (advanced).

    Group settings override organizational units. Learn more

  4. Go to Security.
  5. Click Local auth settings. Learn about Local auth settings.
    Tip: Quickly find a setting by entering text in the search box at the top.

Users are blocked or forced into certain sign-in methods

Users who usually use a local PIN or password are now forced to perform a full online sign-in (GAIA/SAML)

Likely Cause

Users have already set up a local auth factor and:

  • For Local auth settings, under Enable local auth factors, you have selected Do not allow the use of local auth factors.
  • You have removed the user from the organizational unit or configuration group.

Troubleshoot

  • In the Admin console, check Local auth settings to see if Enable local auth factors has been switched from Allow the use of local auth factors to Do not allow the use of local auth factors.
  • Ask the user to complete the online sign-in. If reauthentication is due to changes to Local auth settings, they will see a screen confirming that they must use their online password for future sign-ins. Users need only go through this re-authentication process once to reset settings after the policy change.

Device password is being requested during a full online reauthentication

Likely Cause

  • For Local auth settings, you have set Enable local auth factors to Do not allow the use of local auth factors and no recovery method has been set up.

Troubleshoot

  • Ask the user to enter the password they normally use to unlock their device. They should see a message informing them that the admin has updated the security policy.

Existing SAML SSO users can’t revert to their online password

Likely Cause:

  • Even if you switch Enable local auth factors from Allow the use of local auth factors to Do not allow the use of local auth factors, SAML SSO users are not allowed to go back to using their online password.

Troubleshoot

  • To reset their authentication method, ask the user to back up their local data, remove their Google Account from the Chromebook, and then re-add it.

SAML SSO users are being forced to set up a local PIN or password at initial sign-in

Likely Cause

  • For Local auth settings, you have switched Enable local auth factors from Do not allow the use of local auth factors to Allow the use of local auth factors. As a result, SAML SSO users are required to create local credentials.

Troubleshoot

  • In your Admin console, for Local auth settings, confirm that Enable local auth factors was recently set to Allow the use of local auth factors.
  • Instruct users to continue the account creation flow.

Issues related to creating, updating, or meeting requirements for local PINs and passwords.

User PIN or password is rejected at initial sign-in during account creation

Likely Cause

  • The user's input doesn’t meet the minimum complexity requirements that you specified under Local auth factors complexityLow, Medium, or High.

Troubleshoot

  • Review the complexity requirements set for that user, group, or organizational unit.
  • Ensure the user is entering a value that meets your required criteria—Specific length and character variety requirements.

Users are receiving persistent notifications to update local PIN or password

Likely Cause

  • You have increased the local authentication factor complexity requirements under Local auth factors complexity.

Troubleshoot

  • Ask the user to go to their device settings and update their local PIN and password to satisfy the new complexity requirements and dismiss the notification. For details, go to Sign in to your Chromebook.

Was this helpful?

How can we improve it?
Search
Clear search
Close search
Main menu
8219462164679233403
true
Search Help Center
false
true
true
true
true
true
410864
false
false
false
false
false