Skip to content

Managing access

Access is the explicit bond: this person may sign in to this resource — optionally narrowed to a specific Windows account, a protocol, and an end date.

Dimension Options
Person Who it belongs to (email identity)
Resource Which machine
Account Which Windows login account (or account-wide)
Decision Allow or Deny
Protocol Console, RDP — or all the resource allows
Expiry Permanent, or an end date (time-boxed / just-in-time)

One person can hold access to several accounts on the same machine, and to many machines — always with the same single authenticator.

Access is created when you invite a person to a resource account, or from the person’s page. Granting access to an already-enrolled person takes effect immediately (they just get a notification email).

  • Deny keeps the record but blocks sign-in — useful to suspend one access without deleting history.
  • Remove deletes the access. The person receives a passive security notice (“your access was removed”) with no instructions — informative, not actionable.
  • Either way, the person’s other accesses and their authenticator are untouched.

Set an expiry when the need is temporary (a contractor, an incident, a migration). When the date passes, sign-in is refused with the access expired reason — nothing to remember to clean up.

By default, a person with no access is simply denied when the resource enforces grants — and you can make this strict per resource with the enforce grants policy: no access record ⇒ no sign-in, full stop. See sign-in policies.

A person’s page lists every access they hold across resources — one place to review and revoke. The audit log records each grant, change, and removal with who did it.