
How to install and configure
UserLock Anywhere
Procedure
Prerequisites
- The UserLock Anywhere feature must be installed and configured on an IIS server. See specific sections below.
- Public IP Address registered in DNS for IIS Server that hosts UserLock Anywhere
- The following Server Manager Roles:
- Web Server (IIS)/Security/Windows Authentication
- Web Server (IIS)/Application Development/.ASP.NET 4.5
1. Install the UserLock Anywhere feature
The UserLock Anywhere feature must be installed on the IIS server allowing the agent to contact the service through the Internet when the network connection is not established. Note that this feature is not installed if you choose “Standard” when you install UserLock.
- Log on to the IIS server to which you want to install UserLock Anywhere.
- If UserLock is already installed, open the Windows Control Panel, select “Uninstall a program”, then “UserLock”, and click on “Change”

- If UserLock is not already installed, launch the UserLock installer and select the “Custom setup” option.
- If UserLock is already installed, open the Windows Control Panel, select “Uninstall a program”, then “UserLock”, and click on “Change”
- Open the “Web Applications” menu, click on “UserLock Anywhere”, then “The feature will be installed….”

- If UserLock protects no IIS application on this server and that you only want to configure UserLock Anywhere in it:
- Run the UserLock console. In the “Agent distribution” view, select the “IIS” line of the IIS server to which you want to install UserLock Anywhere. Right click and select “Install”, this will deploy UserLock server name(s) to the registry of that server.
- Log on the target IIS server. Run Regedit. Delete the following registry key:
HKEY_LOCAL_MACHINE \ SOFTWARE \ ISDecisions \ UserLock \ IIS \ VolatileNOTE: This step can be ignored if the IIS agent is installed on the server to protect an IIS application.
2. Add the UserLock Anywhere application to IIS
To add UserLock Anywhere application in IIS, there are two possibilities. You can install it with a command line tool or via the IIS Manager console.
To install it with a command line tool: Run UserLockInstaller.exe (%ProgramFiles(x86)%\ISDecisions\UserLock\UserLockInstaller)

Choose “Install UserLock AnyWhere” (Here n°5), then go directly to step 6.
To install it via the IIS Manager console:
- In IIS Manager, create a new Application Pool with the following parameters:
- Name: ‘UserLockProxyAppPool’
- .NET CLT version: =>
- .NET CLR version v4.0.30319
- Managed pipeline mode: Integrated

- Navigate to Advanced Settings/Process Model/Set the value “Load User Profile” to True

- At the default website level, create a new application that uses the previously created application pool:

- Configure this application with the Userlock Anywhere folder under the UserLock installation folder. By default: “%ProgramFiles(x86)%\ISDecisions\UserLock\Webproxy”. Click OK to continue.NOTE: If using the delegated mode, please refer to prerequisite below.

- Select Application settings / Authentication:
- Disable “Anonymous Authentication”
- Enable “Windows Authentication”

- Open the menu Server Properties in the tab General and change the setting Public URL with the path to the external URL.

Delegated Mode
The delegation must be enabled if the IIS server is not hosted on the same as the UserLock server.
Prerequisite:
A customized install of UserLock is required on the delegated server (the same one where IIS is installed), using the same executable file as for the primary UserLock server. However, the only feature to be installed should be UserLock Anywhere.
- In “Active Directory Users and Computers,” open the properties of the machine where the IIS server is.
- Open the Delegation tab.
- Select “Trust this computer for delegation to specified services only,” “Use any authentication protocol,” and click on “Add…”.

- Click “Users or Computers…”, and search for the machine where the UserLock server is located.
- Select “cifs” service type and click on “Ok.”

Optionally
Suppose you want to accelerate the contact process to UserLock Anywhere when the agent does not directly connect with the UserLock server. In that case, we advise deploying the FQDN name of the UserLock server using a group policy, as explained here.
This will allow the agent to discard the connection to the UserLock server faster and change the alternative through the Internet to UserLock Anywhere link.
3. Make sure that on the target computers, the Desktop Agent is installed and the UserLock Anywhere URL is deployed
For UserLock Anywhere to work on a target computer, the Desktop Agent must be installed, and the URL must be registered.
Once UserLock Anywhere is configured, UserLock will deploy its URL to all computers on the site.
You will need to deploy this URL for computers without a network connection. There are two different ways to do this:
- Manual creation of the registry value:
Open the registry on the target machine.
Navigate to the key ‘HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon’
Create the registry value ‘UserLockInternetUrl’ (type REG_SZ) and write the URL in its content. - Or deploy the URL using Group Policy as explained here.
4. Test the UserLock Anywhere connection
A simple test can be carried out to confirm UserLock Anywhere is functioning; enter into a browser the URL entered in step 6, above (defined in Server Properties in the tab General).
You should receive a confirmation that the service is reachable:

Disconnect and lock user sessions over the Internet.
This feature, available since UserLock 11.0.1 and based on UserLock Anywhere, can be activated by configuring the new advanced setting “SessionsWithoutNetworkLogoffAgentInternet” (from the UserLock console, press the F7 keyboard key to display the advanced settings dialog). This allows logon hours or time quotas to be respected, even if a computer is not connected to the corporate network.
Configure “SessionsWithoutNetworkLogoffAgentInternet” with the number of minutes the Desktop agent will wait between each request for the list of sessions to interact with. We recommend that you do not configure with less than 10 minutes not to increase the workload of UserLock. By default, this feature is disabled (-1). Group policies can configure this setting (see here for details).

Troubleshooting
What to do if connections are slow with UserLock Anywhere?
Connections to workstations used at home by end users and via UserLock Anywhere may be slow after entering the password or the MFA code.
This is due to a problem with caching DNS entries that do not exist in the Internet Service Provider’s DNS servers used by the internet router.
One way to solve this problem is to modify the configuration of the DNS servers of the internet router, for example, by configuring the Google DNS servers (8.8.8.8 and 8.8.4.4).
LOGON is a pan-asian company operating in China, Hong Kong (HK), India, Singapore, Malaysia, Indonesia, Vietnam, Philippines and Thailand. LOGON has local dedicated trained product specialists in Hong Kong, Guangzhou, Kuala Lumpur, Mumbai and Bangalore. LOGON acts both as value added reseller and sole distributor for award winning software solutions. Customers can buy new licenses, purchase upgrades and renewals from any of our local offices. Contact us for first line support during evaluations, PoCs. We offer best practices consulting services and classroom & online training. Check our site for latest offers, special discounts, bundle deals, etc..








