website/docs/endpoint-devices/authentik-agent/device-authentication/local-device-login/windows.md
Windows Credential Provider (WCP) is a component of the authentik Agent that allows logging in to Windows devices using authentik credentials.
Currently, only local login is supported; RDP login is not yet available and is under development.
:::warning
Local device login requires that the authenticating user is authorized to access the device. Access is controlled via device access groups, which always apply. On Enterprise, direct device bindings (users, groups, or policies bound directly to the device) also affect access. If no device access group or direct binding is configured with the appropriate bindings, all login attempts will be denied.
windows-devices) and click Create.:::info You can also assign a device access group during enrollment by selecting a Device group when creating the enrollment token. :::