AuthLite by AuthLite is an affordable solution for secure two-factor authentication with Windows domain member workstations. It enhances Windows password security with a one-touch token for each user. It uses the familiar Windows login interface, works online and offline, and requires plugging in the USB key, tapping the contact, and entering your password. AuthLite integrates with Active Directory for 2-factor authentication. Users provide a One-time Passcode (OTP) with their AD password. AuthLite validates the OTP and attaches a special group to the user's Kerberos session to indicate two-factor login, allowing systems to check the login method and control access based on 2-factor authentication. AuthLite secures Domain Admin accounts by eliminating the 'Pass the Hash' (PtH) attack vector, limits user privileges, and requires two-factor logon for access to the Domain Admins group SID. It provides secure two-factor authentication even in cached or offline mode using the HMAC/SHA1 Challenge/response feature of the YubiKey token for mobile Active Directory workstations. AuthLite integrates with Microsoft RADIUS and LDAP for VPN authentication and is compatible with current VPN servers and software. It supports various platforms including Windows, MacOS, and Linux. AuthLite keys (YubiKeys) emulate a USB keyboard, requiring no drivers. Any modern workstation can use the OTP key Server software. Control user logins with 2-factor security and manage workstations via cached/offline mode. AuthLite is a one-time purchase with no repeat costs. The per-user price includes software license and token. YubiKey tokens have no battery or lifetime limitations, and AuthLite includes lifetime maintenance. AuthLite supports zero-client two-factor workstation logons, workstation safe mode operations, and Remote Desktop 2FA over Remote Desktop Protocol with Remote Desktop Gateway / RemoteApp / RDWeb / RD Web Client. It also supports VPN and RADIUS Configuration using IAS/NPS for RADIUS with AuthLite. AuthLite is compatible with OATH Time-based One-time passcodes (TOTP) generated by smartphone soft-token apps, useful for authenticating to a 2-factor system from a smartphone. Soft tokens cannot normally be used for logging into laptops that are offline from the LAN. Use YubiKeys for this use case. There is a feature to create separate 'Offline' OATH tokens, but usability is challenging as the user must choose between online or offline tokens based on LAN visibility.