Global Whitelisting of relevant WEB-Users
In Web Access, it is possible to check whether an account exists or not, even if it has no TS Plus rights. It can also be used to check whether logins exist or not—even for irrelevant logins. This was also criticized in our external penetration test.
It should be possible to specify an AD group to which relevant WEB Access users must belong. TS Plus should then behave in such a way that when users who are not assigned to the whitelist AD group attempt to log in, it acts as if the user does not exist.

Log in to comment and vote
No comments yet
Be the first to share your thoughts.