Skip to main content

PIV-D Feature Matrix

The Workspace ONE PIV-D Manager frees you from carrying a smart card reader to access your PIV or CAC credentials. Workspace ONE PIV-D Manager integrates with various derived credential providers or a YubiKey accessory. Learn more about the supported configurations for Workspace ONE PIV-D Manager when using third-party providers and the differences between Android, iOS, iPadOS, and Samsung Knox.

PIV-D Feature Matrix

The PIV-D Feature Matrix shows the availability of certificate-based authentication (CBA) and S/MIME based on the credential source and the mobile device type. The credential source is one of the following:

  • Issuance - Credentials are issued to the PIV-D Manager app and then stored securely on the device. The following are supported issuance sources:
    • DISA Purebred
    • Entrust
    • Intercede
    • Xtec
    • Workspace ONE UEM
    • AuthentX ID by Xtec
  • Accessory - Credentials are stored on an accessory connected through NFC or by being plugged in. The following is the only supported accessory:
    • YubiKey by Yubico

Feature/Device Availability

In some instances, there are dependencies for feature availability on certain devices. The following shows when a feature is available on a device.

  • CTK - Availability depends on the Apple Persistent Device Token extension, also known as CryptoTokenKit (CTK) provider.
  • DI - Availability depends on the direct installation of certificates to the Android device key store by the PIV-D Manager app.
  • MDM - Availability depends on the mobile device management (MDM) capability of the operating system.
  • CTK/MDM - Availability depends on either CTK provider or MDM.
  • * - Availabilty on a device.

Credential Source: Issuance

FeatureRegistered iOS or iPadOSRegistered AndroidManaged iOS or iPadOSManaged AndroidManaged Knox
Workspace ONE Boxer email CBA*****
Workspace ONE Boxer email S/MIME*****
Microsoft Outlook CBACTK*DI*CTK/MDM*MDM*MDM*
Microsoft Outlook S/MIMECTK*DI*CTK/MDM*MDM*MDM*
Native mail client CBACTK*DI*CTK/MDM*MDM*MDM*
Native mail client S/MIMECTK*DI*CTK/MDM*MDM*MDM*
Workspace ONE Web website CBA*****
Native browser website CBACTK*DI*CTK/MDM*MDM*MDM*
Wi-Fi connection CBACTK*DI*CTK/MDM*MDM*MDM*
Third party VPN CBACTK*DI*CTK/MDM*MDM*MDM*
Digitally sign PDFs*****

Credential Source: Accessory

FeatureRegistered iOS or iPadOSRegistered AndroidManaged iOS or iPadOSManaged AndroidManaged Knox
Workspace ONE Boxer email CBACTK* CTK*  
Workspace ONE Boxer email S/MIMECTK* CTK*  
Microsoft Outlook CBACTK* CTK*  
Microsoft Outlook S/MIMECTK* CTK*  
Native mail client CBACTK* CTK*  
Native mail client S/MIMECTK* CTK*  
Workspace ONE Web website CBACTK* CTK*  
Native browser website CBACTK* CTK*  
Wi-Fi connection CBACTK* CTK*  
Third party VPN CBACTK* CTK*  
Digitally sign PDFs*****

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…