Short answer: The rollout follows the same four phases whether you have 20 employees or 2,000: verify the infrastructure you already have, decide how you will operate, pilot with a small group, then roll out in waves. Headcount changes the issuance logistics, not the sequence.
1. Verify what you already have
Door readers first. Before committing to volume, test a card against your own readers: the enrolled finger must grant access, and a wrong or absent finger must be denied. See: Ordering cards. Both must behave correctly before a reader counts as compatible. See: Supported door readers.
For digital sign-in – if your cards are ordered with FIDO2 – two things must be checked before deployment. Does your identity provider support FIDO2 – in Microsoft Entra ID this is an administrator setting, disabled by default. Do your devices support FIDO2 security keys: sign-in is supported on iPhone over NFC, and on Windows with a built-in or external NFC or smartcard reader. Survey the device mix before committing to passwordless sign-in for all users. See: Supported services and Platform support for sign-in.
2. Decide how you will operate
Choose the enrolment model carefully. Self-enrolment with the app suits smaller organisations that trust employees to manage their own credential, and distributed teams without an issuance desk. Centralised enrolment at the station gives operator-verified identity, provided enrolment is supervised. Cards issued at the station are also managed there – they cannot be re-enrolled from the app. See: Enrolment options: which is right for you?
Define these processes before the first card is issued:
- Issuance order: encode door credentials before fingerprints are enrolled. Biometric registration of a door application is only possible before enrolment – an application added afterwards opens the door without a fingerprint check See: How do I register an application to use biometrics?.
- First setup: until a PIN is set, a card can be set up by anyone in possession of it. Treat cards before first setup like bank cards before activation – keep them controlled, and have users set them up promptly on receipt
- Lost or stolen cards: who revokes, in the access system and in every identity provider
- PIN lockout: the PIN cannot be recovered, so a locked card means a replacement – and wrong attempts count from first setup, including during enrolment. Keep spare cards.
- A replacement card is a new card: enrolment, credentials and registrations do not carry over
- A fallback for the user: decide in advance what happens on the day a card is forgotten, lost or locked – a temporary credential, an escorted entry, or a same-day replacement – so the decision is not made at the door
- Joiners and leavers: issuance and revocation tied to the existing HR process
- Internal support: who answers user questions, with a short guide for users and one for those answering
3. Pilot with a small group
Ten to twenty users, covering every platform in your device mix. Run the complete lifecycle, not only the successful flow: issue cards, use the doors, sign in, and replace one card deliberately so the replacement process is tested before it is needed. Include the everyday exceptions: a forgotten card, and confirmation that the visitor flow is unaffected. Check that the event log distinguishes a failed fingerprint from an unknown card, and that the failure credential is registered and denied. See: What happens when there is no biometric match? Revise the internal instructions where the pilot showed gaps.
4. Roll out in waves
Phase by site or team, or by risk – highest-security zones first, where the gain is largest. Running old and new cards in parallel during the transition is normal; what matters is a firm end date for the old cards, communicated repeatedly and enforced. New joiners receive IDEX cards from day one of the transition.
Keep communication to users short: what changes, what to do if something fails, and where to get help. Track registrations per wave, together with failed attempts and support requests – the last two should fall from one wave to the next.
For digital sign-in, separate registration from enforcement. Let each wave register their cards first, monitor uptake, and only require the card – or remove weaker sign-in methods – once coverage is in place. Enforcing before users have registered leaves them without a sign-in method.
What changes with size
The enrolment model follows your assurance requirement, not your headcount – a small organisation with strict requirements still benefits from an enrolment station. What size changes is throughput: enrolment is one person at a time, so the question is how many sessions you need and how long they take. See: Fingerprint enrolment options.
Around 20–50 users: the whole organisation can be enrolled in a day or two. One named owner, one station or one person guiding self-enrolment, cards handed out individually. The pilot can simply be the first few users.
Around 100–500: throughput becomes the constraint. Book enrolment sessions by team rather than opening a queue, and keep each session small enough to absorb without waiting. Encode and prepare the cards before the session, so the session itself is enrolment only.
Around 1000+: run several stations in parallel, or a structured self-enrolment campaign, and go site by site. Tie issuance and revocation into the joiner and leaver process, so the steady state does not need a campaign at all.
Next step
Chosen a model? See Enrolment options: which is right for you? for the decision behind phase 2.