Installation and Configuration

Client Installation

HYPR Workforce Access for Windows can be installed silently or using the installer user interface. Administrative access to the target workstation is required. Introduction of new keys will be made as a result of a successful installation.

Silent Install

The HYPR Workforce Access Client can be installed on the command line using msiexec.

Command Line Parameters

Parameter Name





The application ID as specified in the Control Center

A character array [0..256]

No default. Mandatory Field.


The URI of the Control Center. Replace with your domain in the example URI below:


This URI must end in /rp

A character array [0..256]

No Default. Mandatory Field.


The email address where support requests will be mailed

A valid email address

No Default. Optional.


The SHA1 or SHA256 PIN Hash of the server SSL certificate. This serves as the Public Key Pinning value.

A SHA1 hash of the server SSL certificate.

No Default. Mandatory.


Certificate template name

A valid certificate template name

Default is User template. Optional.


Installation Token used for endpoint protection

A valid InstallToken generated in the Control Center

No Default. Mandatory.


Company logo displayed in the app.

Path to an image

HYPR Images are set by default. Optional.


Custom background image displayed in the app.

Path to an image

HYPR Images are set by default. Optional.

You can learn more about additional parameters that could be configured during the installation in this page.


Example Installation

From a command prompt with administrative privileges

msiexec.exe /qn /i .\EmployeeAccess.msi HYPRAPPID="WindowsUnlock" HYPRRP="" HYPRSUPPORT="[email protected]" HYPRHASH="abcdef...fedcba" HYPRTEMPLATE="HYPRUser" HYPRINSTALLTOKEN="c8d2rf05b-b6db-4bc3-ateb-abb6302c48fd" HYPRCUSTOMLOGO="C:\\foo\\bar" HYPRCUSTOMBACKGROUND="C:\\foo\\bar"



  • The Alternate Subject Name must include the User Principal Name (UPN) in the certificate template

  • Default user template User will be used if HYPRTEMPLATE parameter wasn't specified

  • The installer file name shall not be changed unless otherwise noticed by HYPR.

Installer user interface

Rather than performing a silent install, you can use the installer wizard provided by HYPR. Double click the .msi installer provided to you by HYPR. You will see the installer user interface Window

  1. Click Next
  1. Accept the End User Agreement Terms
  1. Enter installation parameters
  1. If any of the four parameters do not meet their required criteria, a warning message will pop up.

Certificate Template can be left blank to make use of default user templates or if you're deploying HYPR on non-domain joined environment.

  1. Click Install

If necessary, when the installation finishes you'll be prompted to restart the workstation to complete the installation.


Upgrading without reboot

If you upgrade from version 6.12.0 to 6.12.0+, a reboot won't be required for most releases. This will be only necessarily on major updates. HYPR will notify customers about these versions that would require a reboot before the release.


Certificate Template Configuration

If you're using the installer user interface for installation and would like to specify the User Certificate Template, then you'll need to set it manually in Registry Editor. See keys and values below.

Registry Keys

Installation requires that keys are installed into the registry of the target workstation. These keys are required for normal functioning of the application.



Application ID

The application ID specified during installation. If you do not specify one this will be blank. This can be updated afterwards by an admin.

Machine ID

A unique identifier for the workstation. This should never be changed

Public Key Pinning

SHA1 hash of the server SSL certificate

Relying Party Url

The URI as provided by the installer

Support Email

The support email for your organization

Certificate Template

Certificate template name

Recovery Pin Text

The text message displayed on the login screen when the user clicks "Don't have your phone?"


New Key Added

After Installation, the following keys will be added to under the following path:

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{C822931E-86C5-4482-85C1-049523A13A09}