Global Whitelisting of relevant WEB-Users

In Web Access, it is possible to check whether an account exists or not, even if it has no TS Plus rights. It can also be used to check whether logins exist or not—even for irrelevant logins. This was also criticized in our external penetration test.

It should be possible to specify an AD group to which relevant WEB Access users must belong. TS Plus should then behave in such a way that when users who are not assigned to the whitelist AD group attempt to log in, it acts as if the user does not exist.



Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
Custom icon

Advanced Security Feature Request

Date

2 months ago

Author

christian.glass@atoria-software.com

Subscribe to post

Get notified by email when there are changes.