Skip to content

Shared accounts

A Windows account on a resource can be personal (one owner) or shared (a role that several named people use — the classic shared Administrator).

Each person invited to a shared account enrolls their own authenticator. At sign-in, everyone types the same Windows username and password — but the second-factor code identifies which person it is. Dynacop resolves the code to the person, and the audit record shows the real human.

Windows account: Administrator (shared)
Code entered: Ayşe's code → recorded as Ayşe
Mehmet's code → recorded as Mehmet

No renaming of Windows accounts, no per-person Windows profiles — the account stays shared, accountability doesn’t.

  • Give a personal account one linked person. Its access follows that person.
  • Mark an account shared when it’s a role. Invite each person who uses it; each gets their own factor and their own audit trail.
  • An account with more than one linked person is treated as shared. You can’t convert it back to personal until only one person remains linked.

On the resource’s account list you can see every linked person, invite new ones, and remove a person’s access individually — without touching anyone else or the Windows account itself. Removing one person’s access doesn’t interrupt the others.

See also: Person ≠ Account · Managing access.