We wish our users to login once only to one PC. Microsoft say we can only do this by limiting them to one designated machine, this is not possible for us.
We need to know that if a particular user did something we can rely on the audit trail.
We understand this may get tricky with Citrix use.
Various things have been suggested particulary HP Protect tools.
Anyone got any views on this or other possible products or solutions?
Thanks to all that replied to my previous question - helpful responses from all of you.
Software/Hardware used:
ASKED:
September 26, 2005 12:13 PM
UPDATED:
March 4, 2008 3:19 PM
You stated: “Microsoft say we can only do this by limiting them to one designated machine, this is not possible for us.”
Why not? Can you be more specific? In Active Directory Users and Computers, if you look in a specific user’s properties, the option is clearly there under the “Account” tab, then clicking on “Log On To…” setting…
Please clarify if I am misunderstanding your issue…
A good 3rd party solution is userlock http://www.pnltools.com/productinfo.asp?productid=17&refid=138
I use it in my AD and have no problems. It is easy to set up and manage, prvides alerts and other tools
If all you’re worried about is an audit trail why bother? Having a good authentication scheme, audit policy and signed usage agreement stating users should not share passwords and that they are responsible for the actions performed using their accounts, you have an audit trail that would stand up in a court of law or a board room.
This is an awesome solution to the posting. Another tool that people seem to have been raving about was userlock.