Skip to content

Person ≠ Account

The most important idea in Dynacop: a person is not a Windows account.

On many servers, several people sign in as the same Administrator. The Windows log then only ever says “Administrator signed in” — it can’t tell you which person it was. Accountability disappears.

Dynacop identity is not derived from the Windows login name. Each person enrolls their own authenticator, tied to their email identity. When they sign in — even to a shared Administrator account — the second-factor code they enter identifies the real person. The audit record then shows the human, not just the account name.

Windows account: Administrator
Real person: ayse@example.com
Session: RDP
Result: Allowed

A Windows account can be:

  • Personal — one owner.
  • Shared — a role that several named people are invited to.

For shared accounts, the code-based identification above is what gives you a real audit trail while everyone keeps using the same login.

Because a person is a single email identity, they enroll once. That one authenticator works for the panel and for every Windows account and machine they’re given access to. Resetting it re-binds everything at once.

Next: Resource, Person, Access.