A computer may have multiple NFC or smart card readers connected for different applications. By default, the GateKeeper Client may detect all compatible readers available to Windows.
If a specific reader should not be used by GateKeeper, you can add its exact device name to the ExcludeNFCReaders registry value. GateKeeper will then ignore that reader while continuing to communicate with other supported readers.
Important: Only exclude readers that should not be used for GateKeeper authentication. If the wrong reader is excluded, users may be unable to authenticate with their NFC or RFID cards.
Requirements
Before proceeding:
- Sign in to Windows with an administrator account.
- Confirm that at least one supported reader will remain available for GateKeeper.
- Record the exact name of the reader you want to exclude.
- Back up the registry before making changes.
Step 1: Identify the Card Reader in Device Manager
- Right-click the Start button.
- Select Device Manager.
- Expand Smart Card Readers.
- Locate the reader that you want GateKeeper to ignore.
- Record the reader name exactly as it appears in Device Manager.
Example:
HID Global OMNIKEY 5025 CL 0Do not shorten, rename, or modify the device name.
The registry entry must match the reader name detected by Windows and GateKeeper.
Step 2: Confirm the Reader Name in the GateKeeper Logs
The GateKeeper logs can help confirm which readers are being detected by the GateKeeper Client.
- Open File Explorer.
- Navigate to:
C:\ProgramData\GateKeeper\Log- Open the most recent GateKeeper Client log file.
- Search the log for terms such as:
readerNFCsmart card- Locate the entry showing the card reader detected by GateKeeper.
- Confirm that the reader name in the log matches the reader name shown in Device Manager.
The
ProgramDatafolder is hidden by default. In File Explorer, enable View → Show → Hidden items if you cannot see it.
Step 3: Open the GateKeeper Client Registry Configuration
- Press Windows + R.
- Enter:
regedit- Click OK.
- Approve the User Account Control prompt.
- Navigate to:
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Untethered Labs\GateKeeper Client\ConfigStep 4: Create the ExcludeNFCReaders Registry Value
- Right-click an empty area in the right pane.
- Select:
New → Multi-String Value- Name the new value:
ExcludeNFCReadersThe value type should be:
REG_MULTI_SZ- Double-click
ExcludeNFCReaders. - In the Value data field, enter the exact card reader name identified in Device Manager and the GateKeeper logs.
Example:
HID Global OMNIKEY 5025 CL 0- Click OK.
Excluding Multiple Readers
To exclude more than one reader, enter each reader name on a separate line.
Example:
HID Global OMNIKEY 5025 CL 0
Identiv SCR3310 v2.0 USB Smart Card Reader 0Do not separate the reader names with commas or semicolons.
Step 5: Restart the GateKeeper Client Service
The GateKeeper Client service must restart before the new registry configuration takes effect.
- Open the Start menu.
- Search for:
Command Prompt- Right-click Command Prompt and select Run as administrator.
- Run the following command:
taskkill /F /IM GateKeeper.Service.Windows.exeThe GateKeeper Bootstrap service should automatically restart the GateKeeper Client service within approximately one minute.
Alternatively, restart the computer.
Step 6: Confirm That the Reader Is Excluded
After the GateKeeper Client service restarts, confirm that GateKeeper no longer detects the excluded reader.
Option 1: Check the GateKeeper Client Application
- Open the GateKeeper Client application.
- Review the NFC or card-reader section.
- Confirm that the excluded reader is no longer displayed.
- Confirm that the reader intended for GateKeeper is still available.
Option 2: Check the GateKeeper Logs
- Return to:
C:\ProgramData\GateKeeper\Log- Open the newest log file.
- Search for the excluded reader name.
- Confirm that GateKeeper is no longer initializing or using that reader.
Option 3: Test Both Readers
- Present a registered GateKeeper card to the excluded reader.
- Confirm that GateKeeper does not respond.
- Present the same card to the approved GateKeeper reader.
- Confirm that GateKeeper detects the card and performs the configured authentication action.
Troubleshooting
The Excluded Reader Is Still Detected
Confirm the following:
- The registry value is named exactly
ExcludeNFCReaders. - The registry type is
REG_MULTI_SZ. - The reader name matches the GateKeeper log exactly.
- There are no extra spaces before or after the reader name.
- The registry value was created under the correct path.
- The GateKeeper Client service or computer was restarted after the change.
If Device Manager and the GateKeeper logs display slightly different reader names, use the exact name shown in the GateKeeper log.
GateKeeper No Longer Detects Any Readers
The wrong reader may have been excluded.
- Open the
ExcludeNFCReadersregistry value. - Remove the reader that GateKeeper should continue using.
- Restart the GateKeeper Client service.
- Confirm that the correct reader is detected again.
The GateKeeper Service Does Not Restart
Restart the computer and check the GateKeeper Client application again.
You can also verify in Task Manager that the following GateKeeper processes are running:
GateKeeper.Bootstrap.Windows.exe
GateKeeper.Service.Windows.exeRemoving the Exclusion
To allow GateKeeper to use the excluded reader again:
- Return to:
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Untethered Labs\GateKeeper Client\Config- Open
ExcludeNFCReaders. - Remove the reader name from the value data.
- If no readers need to be excluded, delete the
ExcludeNFCReadersvalue. - Restart the GateKeeper Client service or restart the computer.
- Confirm that the reader is detected by GateKeeper again.
For any additional questions or concerns regarding faster 2FA, proximity settings, computer locking, password management, or compliance, please contact GateKeeper Enterprise support using the Support Ticket form on https://gkaccess.com/support/ or email support@gkaccess.com.
Comments
0 comments
Article is closed for comments.