SessionLimit v2
  • Infrastructure Documents
  • Overview
    • What is SessionLimit
    • FAQs
    • Road Map
    • Licensing
  • Planning
    • POC Requirements
    • Supported Configurations
    • Windows Server Requirements
    • SQL Server Requirements
    • Agent Requirements
      • .Net Framework 4.7.2
    • Other Requirements
    • Network Considerations
    • Design
      • Single Deployment
      • Distributed Deployment
  • Deployment
    • GMSA Account for Application Pool
    • DNS Service Record for Agent Autodiscovery
    • Installing Microsoft SQL Server
    • Internet Information Service Installation
    • .NET Core 8.0 Download and Install
    • .Net Framework 4.7.2 Download and Install
    • HTTPS Certificate
    • Installing SessionLimit 2.0
    • Upgrading SessionLimit
      • Upgrading SessionLimit 2.0.12 to 2.0.13
      • Upgrading SessionLimit 2.0.13 to 2.0.14
      • Upgrading SessionLimit to 2.0.15
      • Upgrading SessionLimit to 2.0.16
      • Upgrading SessionLimit to 2.0.17
      • Upgrading SessionLimit to 2.0.18
      • Upgrading SessionLimit to 2.1
      • Upgrading SessionLimit to 2.1.2
      • Upgrading SessionLimit to 2.1.3
      • Upgrading SessionLimit to 2.1.4
    • First Time Wizard
    • Agent Deployment
  • Managing
    • Logging to SessionLimit 2.0
    • Dashboard (Home)
      • General Dashboard
      • My Dashboard
      • Agents Dashboard
    • Policy
      • Session Protection Policy
      • 2FA Policy
    • Limitations
    • Endpoint Management
      • Users
      • Computers
    • Settings
      • General
        • Server Settings
        • LDAP Settings
        • Notification Settings
          • General Notification
          • E-Mail
          • SMS
        • Syslog Settings
        • Syslog Message Settings
      • Advanced Settings
      • 2FA
      • Agent
    • Events
    • Reports
    • Role Management
    • License Management
      • Online License
    • Syslog
      • Logon Operations
  • Agent
    • Session Control
    • 2FA
  • Tips&Tricks
    • SQL Express Usage
    • Fixing 500.19 web.config error
    • Enable HTTPS Redirection in IIS with HSTS
    • Using GMSA Account in Application Pool
    • Give Database Access for GMSA Account
    • What are the SessionLimit protection states?
    • Securing Windows Server
Powered by GitBook
On this page
  • Schedule
  • Max Attempt Count
  • Buttons Meaning in 2FA Authentication Policy
  • Policy Assign
  • Update Policy
  • Policy Assign Details
  • Delete Policy
  1. Managing
  2. Policy

2FA Policy

Scope: SessionLimit 2.0

PreviousSession Protection PolicyNextLimitations

Last updated 10 months ago

The 2FA policy is to ensure that end users undergo secondary verification when logging into their computers. It is activated as soon as the user logs in and asks the user for a 6-digit OTP code. OTP codes can be obtained by the following 2 methods.

  1. SMS

  2. Authenticator mobile app

Although the SMS feature can be selected here, it has 2 prerequisites.

  1. In the , the attribute containing the users' mobile phone numbers must be selected.

  2. must be made.

Care should be taken when implementing 2FA policies. If the affected users do not have an authenticator setting at the time the policy is assigned, or if it is applied when they do not see 2FA activated, the session will be automatically logged out at the end of the specified period. Care should be taken when activating the policy to avoid situations such as data loss on affected computers.

Schedule

Provides 5 different options. Decides how often the 2FA verification should be made by the end user.

Never: Never performs 2FA verification.

When logging on from a new machine: If a different computer is logged in than the last computer with 2FA, it asks the user for 2FA verification,

At Every Logon: It asks for 2FA verification for every login,

At the first logon: It asks for 2FA verification from the user's first session of that day. This option is independent of which computer it is logged in from.

Every X Day(s): This option only asks for 2FA verification once in the specified day range. 2FA verification must be performed in the 2 sessions to be opened after this period.

Max Attempt Count

This is the number of times an incorrect code is allowed to be entered when the end user tries to log in to the computer with 2FA. By default, it is 3, the minimum value is 2 and the maximum value is 5.

Buttons Meaning in 2FA Authentication Policy

  1. Policy Assign: The policy is assigned to the user, security group or Organizational unit. This action takes immediate effect if performed and enables the user to perform secondary verification by displaying a 2FA screen in active sessions. Sessions are only intervened in systems with agent installed. The session on the system that does not have an agent installed cannot be interfered with.

  2. Update Policy: It is used to change 2FA policy settings.

  3. Policy Assign Details: Displays the assignment information of the policy.

  4. Delete Policy: It is used to delete the policy.

Policy Assign

  • Choose domain

  • Select the criteria to be searched in the search user field.

  • Enter at least 1 character in the search field, press the search button.

  • Select the AD objects you want to protect with 2FA Policy from the list and press the Add button.

  • Once you finish adding to the list, save it with the Save button.

  • If you want to remove it after adding it to the list, you can delete a single object with the Delete button, or the entire list by clicking remove list.

Update Policy

Update policy screen is used to make changes to the existing policy.

  1. Which type of 2FA method should be used?

  2. In what type of sessions should it be used? etc.

Policy Assign Details

The users, groups and OUs to which the policy is applied are displayed on the Policy Assign Details screen. deleting and clearing the list operations can be carried out from this screen.

Delete Policy

It is used to delete the policy. Once the policy is deleted, 2FA transactions related to this assignment will not occur again.

LDAP settings
SMS settings
Buttons under Actions Column
Assign 2FA Policy
Policy Assign Details