Beyond Identity began rolling out the new Platform Authenticator v3.0.0 (Beta) release on August 4, 2026.
Beyond Identity Authenticator 3.0.0 introduces the Universal Platform Authenticator — a single, unified application that replaces the previous per-platform authenticators with one consistent experience across Windows, macOS, Linux, iOS, and Android.
Note: This is a Beta release, intended for early adopters and pilot deployments. Existing 2.x installations are not automatically migrated during the Beta — you opt in by installing 3.0.0, or your IT administrator deploys it. Automatic migration from 2.x turns on once the Beta concludes.
What’s New
| Platform | Feature Description |
|---|---|
| All | One Unified Authenticator A single application delivers the authenticator on Windows, macOS, Linux, iOS, and Android, with the same interface, behavior, and authentication flows on every platform. Linux gains a full graphical application, where previously it was headless only. |
| Windows, macOS, Linux | Simpler Installation and MDM Deployment One installer per platform, roughly 3× smaller than 2.x on Windows and macOS. On Windows, a single MSI handles both per-user and system-wide installs and chooses the right one automatically from the deployment context. It deploys cleanly through Microsoft Intune, SCCM, PDQ, and Jamf, and upgrades in place from 2.x. On macOS, a single .pkg covers MDM, system, and user deployments. On Linux, the installer is a direct download with an architecture selector — available as an AppImage with automatic updates, or as native .deb and .rpm packages for your distribution’s package manager. |
| All | Faster Startup and Sign-In The application starts and completes sign-in flows more quickly than the 2.x authenticator. |
| All | Automatic Updates with Rollback A separate updater process keeps the authenticator current in the background and rolls an update back automatically if it fails its health checks. Release channels let organizations pilot new versions before rolling them out broadly. |
| All | Command-Line Interface A new CLI supports scripting and IT automation — manage credentials, enroll Desktop Login, process enrollment and authentication links directly, and configure settings. None of this was available in the previous application. |
| All | Redesigned Hardware-Backed Key Protection A new cryptographic engine binds keys directly to each platform’s secure hardware — the TPM on Windows and Linux, the Secure Enclave on Apple devices, and the Android Keystore — selecting the strongest protection the device offers. All communication with the TPM uses encrypted sessions. On Windows, newly enrolled credentials no longer go through the Microsoft CNG providers and are therefore no longer tied to DPAPI, and so no longer to the user’s Windows password — making them more resilient to password resets and user-profile problems. Credentials carried over from 2.x continue to work as before. |
| macOS, Linux | Hardware Security Keys Beyond Windows PIV security keys such as YubiKey can now be used with Beyond Identity on macOS and Linux, where support was previously Windows-only. Enroll a credential onto the key and manage it — change or reset its PIN, inspect it, remove it — from the application or the security-key CLI command. |
| Windows | Desktop Login Enhancements Enroll, unenroll, and change your PIN from either the application UI or the CLI, and sign in with a PIV hardware security key in addition to the virtual smart card. |
| All | Built-In Troubleshooting and Diagnostics A Troubleshooting screen — and the troubleshoot CLI command — runs connectivity and sign-in self-checks covering internet and Beyond Identity cloud reachability, DNS, TLS, system clock, proxy and loopback configuration, credential and identity state, and platform-specific checks such as camera permission, the Intune MDM certificate, and the Linux desktop session, keyring, and tray. Each check reports Pass, Warning, or Fail with guidance on how to fix it, and results stream in as they finish.Report an Issue packages a diagnostics bundle and sends it to Beyond Identity support in one step; the diagnostics command saves the same bundle locally to attach yourself. Logging is more consistent across all platforms for faster support. |
| All | Activity History A Show History page in the application, and the history CLI command, list recent activity on the device — successful and failed sign-ins, passkey changes, GPG key changes, application updates, and Desktop Login enrollment — most recent first. History is stored only on the device, contains no secrets, and keeps just the most recent events. |
| All | Additional Languages Available in English, French, German, Japanese, and Spanish. |
Platform Support
| Platform | Minimum OS |
|---|---|
| Windows | Windows 10 or later (x64 and ARM64) |
| macOS | macOS 11 (Big Sur) or later (Apple Silicon and Intel) |
| Linux | Ubuntu 22.04 or later, or any distribution with glibc 2.34 or later (x64 and ARM64) |
| iOS | iOS 13.0 or later |
| Android | Android 9.0 or later |
Upgrading from 2.x
- The upgrade is backward compatible — existing passkeys and credentials carry over.
- Windows: the single 3.0.0 installer replaces the separate 2.x user and system installers.
- macOS and iOS: 3.0.0 and the legacy 2.x application cannot be installed at the same time, as they share paths and identifiers. 3.0.0 takes its place.
- During the Beta, existing 2.x installations are not auto-migrated. 3.0.0 is installed deliberately — you opt in, or your IT administrator deploys it.
Comments
0 comments
Please sign in to leave a comment.