Prerequisites:
- Encoding DESFire credentials on IDEX cards
- Supported door readers
- An IDEX card that has been encoded and enrolled
When a card is successfully read by a door reader with a biometric match, your access management system will see the credential value saved on the card. As with any other DESFire credential, this credential value must be given permissions by the access control system for it to be authorised to open a door.
This is commonly achieved either by attempting access with the credential and then checking the access control system for the credential, or by adding the credential to the system automatically or manually depending on the credential generation system.
It is generally recommended to only grant permissions to a biometric credential after biometric enrolment or after revoking biometric management rights, so a card being lost or stolen does not pose a security risk.
It is also recommended, when adding credentials by attempting access, to attempt access with both a biometric match and a biometric no-match to ensure that biometric enrolment and configuration was successful. If it was successful, the biometric success credential should only appear once
See: What happens when there is no biometric match? and The door opens without a fingerprint match.