SBN

Windows Group Policy for Login Security

The use of Windows Group Policy is often the tool of choice for the strict administration of Active Directory (AD) user accounts. But for logon and access policies, Group Policies can be tedious to configure, particularly so for small and medium-sized business (SMBs) with limited on-site IT expertise. 

GDPR introduction has upped the stakes

All business, including SMB’s, must be looking to protect confidential data from unauthorized access, particularly with the GDPR (General Data Protection Regulation) now in full force. According to cybersecurity expert Graham Cluley, many businesses could see their reputations left in tatters if they fail to shore up their defenses and are hit with crippling GDPR fines.

UserLock takes the strain out of administering AD user login access.

It simplifies these processes by providing real-time management of user logins for multiple session types, workstation access restrictions, session monitoring, and detailed auditing. Agent deployment is a breeze and with a pricing structure based on maximum simultaneous user sessions, it’s affordable for SMBs and enterprises alike.

UserLock Logon Protect

Granular Controls for User and Administrator Accounts

With UserLock, connection rules and restrictions can be applied to AD user and administrator accounts, groups, and OUs and you can create temporary time-limited accounts for guests and contractors.

Rules are extremely versatile as you can set the number of initial access points to control points of entry into the network and concurrent user account logins. This is something AD and Group Policy are notoriously lacking in. The elderly LoginLimit tool was updated recently to support Windows 2012 R2 AD servers but is only capable of blocking all concurrent sessions.

Users can be restricted to specific AD computers and IP address ranges, limit access with time periods, set session lengths and apply time quotas.

Rules provide granular controls as they can be applied at AD group levels for general protection of large user bases and augmented with individual user rules which take precedence.

To further help improve user security behavior, awareness and stop password sharing in the workplace, is the option to warn users if their account is being used to logon to another computer. If this occurs, they’ll receive a pop-up message showing the computer in use and advising them to contact their administrator who will also have received an email alert from UserLock.

Remote Session Management

UserLock administrators can also interact with selected sessions by clicking on them in the console and logging users off, locking the workstations and resetting them. The blocking feature means you can instantly block a user and stop them reconnecting to any system while we investigated their activities.

Detailed reports are available for logon and logoff activities, logons denied by AD and UserLock, failed logins and concurrent session history. They can be scheduled to run at regular intervals or triggered by an event and exported to a range of formats including PDF, XLS, CSV, and HTML. Reporting is easily good enough to satisfy GDPR compliance and external auditors.

UserLock takes the strain out of administering AD user login access. An important differentiator of UserLock is it complements AD and requires no modifications to its schema. It is the perfect access security partner for Windows Active Directory environments.

Read the entire review of UserLock from IT Security Guru

Find out for yourself with a free fully functional 30-Day trial of UserLock 

The post Windows Group Policy for Login Security appeared first on Enterprise Network Security Blog from ISDecisions.

*** This is a Security Bloggers Network syndicated blog from Enterprise Network Security Blog from ISDecisions authored by Chris Bunn. Read the original post at: https://www.isdecisions.com/blog/it-security/windows-group-policy-login-security/

Secure Guardrails