Security Settings¶
The Security section of the organization allows you to configure and strengthen the security rules applied to all users and resources (computers, containers). These settings are defined at the global organization level and apply to all members.
Access: domain Organization > dashboard General > tune Settings > Security.
Organization security settings page.¶
This page groups two distinct blocks: the organization’s global security settings, and the session policies applied to computers and containers.
Security¶
Enforce 2FA¶
Enables mandatory two-factor authentication (2FA) for all organization users.
As long as 2FA is not enabled on their account, users cannot connect to computers or containers.
Recommended to comply with security best practices (stronger protection against credential theft).
Tip
2FA should always be enabled: it’s the most critical security measure to protect the organization’s accounts.
Restrict Container Profile Creation by Group Admins¶
When enabled, group administrators will no longer be able to create new container profiles in this organization.
Restrict Multi User Feature (Timer)¶
When another user tries to connect to a computer/container already in use, a confirmation message is displayed to the current session user.
That user must confirm whether to allow the simultaneous connection.
If no response is given within 30 seconds, access is automatically granted to the second user.
This mechanism makes it possible to:
control concurrent access to machines,
avoid blocking a user from joining a session,
maintain productivity while keeping a level of human validation.
Tip
In environments where confidentiality is a priority (audit, finance…), it’s recommended to limit multi-user sessions.
Session Policies¶
Manages the permissions and restrictions applied during remote sessions.
Note
These settings apply to the organization and inherit by default from the policies defined at the instance level. Specific groups can override them later (see Group Settings).
Note
Each setting has a three-state dropdown (showing the value inherited from the instance in parentheses, e.g. Disabled (Instance)) and a Not Locked / Locked toggle. See Common UI Controls for the full detail of this mechanism.
Clipboard¶
Setting |
Description |
|---|---|
Clipboard Read |
Controls whether users of this organization can read the clipboard of remote devices. |
Clipboard Write |
Controls whether users of this organization can write to the clipboard of remote devices. |
Tip
In sensitive or regulated environments (production data, the financial sector…), it’s recommended to restrict clipboard access.
File Transfer¶
Setting |
Description |
|---|---|
File Transfer |
Allows file transfer with remote devices. |
Printer¶
Setting |
Description |
|---|---|
Printer |
Allow printing (Windows only, requires a RAW TCP printer on port 9100). |
Sessions¶
Setting |
Description |
|---|---|
Auto Disconnect on Idle Sessions |
Defines whether a session should automatically end after a period of inactivity. |
Tip
The auto-disconnect delay is worth adjusting to context: 15 minutes for critical environments, 30 minutes or more for standard use.