Person ≠ Account
The most important idea in Dynacop: a person is not a Windows account.
The problem with shared accounts
Section titled “The problem with shared accounts”On many servers, several people sign in as the same Administrator. The Windows log then only ever says “Administrator signed in” — it can’t tell you which person it was. Accountability disappears.
How Dynacop resolves it
Section titled “How Dynacop resolves it”Dynacop identity is not derived from the Windows login name. Each person enrolls their own authenticator, tied to their email identity. When they sign in — even to a shared Administrator account — the second-factor code they enter identifies the real person. The audit record then shows the human, not just the account name.
Windows account: AdministratorReal person: ayse@example.comSession: RDPResult: AllowedPersonal vs shared accounts
Section titled “Personal vs shared accounts”A Windows account can be:
- Personal — one owner.
- Shared — a role that several named people are invited to.
For shared accounts, the code-based identification above is what gives you a real audit trail while everyone keeps using the same login.
One authenticator, everywhere
Section titled “One authenticator, everywhere”Because a person is a single email identity, they enroll once. That one authenticator works for the panel and for every Windows account and machine they’re given access to. Resetting it re-binds everything at once.
Next: Resource, Person, Access.