Blog, ISDecision Blog, UserLock
UserLock 12.2 Now Live | IS Decisions

What’s new in UserLock 12.2
This article was originally published by LOGON’s partner IS Decisions. Click here to view the original article.

LOGON is a certified IS Decisions partner in Asia.
Contact our specialist for more information on the product release.
New: Enhance MFA experience and security with UserLock’s custom credential provider
Thanks to the new custom credential provider, UserLock multi-factor authentication (MFA) now looks and feels even more like part of the native Windows logon process. You can now offer end users a more intuitive and familiar interface for MFA and extend its capabilities beyond the Windows login.
Here’s how UserLock MFA now visually looks like part of the Windows login process, even when the user is offline:

The new credential provider also establishes the necessary framework to implement the most requested feature from our community: the ability to enforce MFA when a user asks to elevate privileges. You asked, and we listened!
Thanks to the credential provider, you can enforce MFA on Windows UAC (user account control) credential prompts displayed when launching administrative tasks (e.g., when disabling the firewall) and during “Run as administrator” requests. This control over privileged access prevents lateral movement and stops privilege abuse.
Advantages of UserLock’s custom credential provider:
- Deliver a seamless user experience by visually embedding UserLock MFA into the Windows login process, even when the user is offline.
- Enhance security by enforcing MFA before your system logs a Windows session.
- Extend UserLock MFA to non-interactive sessions, including MFA on Windows UAC (User Account Control) credential prompts displayed when launching administrative tasks and during “Run as administrator” requests.
- If you exceed your current session limit, you can identify and remotely close an open session directly from the Windows login screen.
New: Enforce MFA on Windows UAC (User account control) credential prompts displayed when launching administrative tasks
Thanks to UserLock’s custom credential provider, you can apply an extra layer of security on elevated privilege requests with MFA on Windows User Account Control (UAC) prompts displayed when launching administrative tasks (e.g., when disabling the firewall).
You can set granular MFA policies for UAC prompts since UserLock recognizes UAC as a separate access type:

This ability to treat UAC as a separate access event also means you can manage, report on, and alert on UAC credential prompts displayed when launching administrative tasks (e.g., when disabling the firewall) and during “Run as administrator” requests.
Here’s an example of UserLock’s UAC event alert options:

UserLock’s ability to apply UAC MFA on a granular level by protected account ensures you can more accurately report on and better meet compliance requirements for MFA on requests to elevate privileges. This is difficult to do with other MFA providers, which often only allow UAC MFA to be applied by machine or show MFA on UAC requests as an RDP MFA event.
Here’s an example of a UserLock UAC event report:

When you require MFA on UAC events, users must complete MFA in addition to their password before performing actions requiring administrative privileges, such as permitting apps to make changes to the device. This added layer of security on privilege elevation requests significantly strengthens your security posture and hardens your Active Directory against common threats.

Advantages of MFA for UAC prompts:
- Mitigate the risk of credential compromise
- Block lateral movement
- Reduce the risk of privilege abuse
- Protect critical system files and folders from unauthorized modification or sharing
- Minimize an insider threat attack
- Meet compliance and cyber insurance requirements
New: Enforce MFA on Windows UAC (User Account Control) credential prompts displayed during “Run as administrator” requests
You can also apply MFA on “Run as administrator” requests, thanks to the UserLock custom credential provider. You can effectively prevent unauthorized privilege elevation and lateral movement within your network and implement a key element of “never trust, always verify” zero-trust security.

Advantages of MFA for “Run as administrator” requests:
- Reinforce privileged access management (PAM) security by blocking privilege abuse
- Prevent lateral movement
- Meet cyber insurance requirements to protect all admin access with MFA
- Protect against attackers’ ability to leverage stolen credentials


User Logon Security for Windows Active Directory
Enable customized, two-factor authentication (2FA) on Windows logon, Remote Desktop (RDP & RD Gateway), IIS, VPN and Cloud Applications. Apply customized login restrictions by user, group or organizational unit (OU).
Get started with UserLock
Start a free trial with UserLock, with 30-day full version, no user limit, and free technical support.


