Identify individual users on shared Windows or Linux accounts by requiring secondary login credentials before Syteca starts recording their activity.
When multiple people share the same computer account (a shared Windows login, or a shared account like root on Linux), Syteca can’t tell them apart from the account name alone. Secondary user authentication solves this by requiring each person to enter separate credentials before they’re allowed to use the computer - those credentials, not the shared account name, then identify them in every recorded session.
The Enable secondary user authentication on login and Allow the use of one-time passwords options cannot be used together. Neither works correctly if both checkboxes are selected. See One-time passwords for the alternative.
The user entering secondary credentials must have the Access to Endpoint via Secondary Auth. permission for the Client, granted via Client permissions. Their secondary user name then appears in brackets after the shared account name throughout the Client Sessions list - for example, WORK\shared-account (janet).
Before a user can authenticate as a secondary user on a Windows Client, or log in to the terminal on a Linux Client with secondary user authentication enabled, they need the Access to Endpoint via Secondary Auth. permission for that Client. This step applies the same way on both operating systems.
Secondary user authentication keeps working offline (no connection to the Application Server), but only for users who have previously authenticated at least once while online. In rare cases (for example, after reinstalling a Client), a user may be unable to log in - an administrator can contact the Syteca Support team for a temporary emergency password.
After a forced restart, the EkranClient service takes about a minute to start. Secondary user authentication doesn’t work during that window.
On the Editing Client (or Editing Client Group) page, select the Authentication Options tab, scroll to Two-Factor and Secondary Authentication, and select Enable secondary user authentication on login.
3
Customize the login message (optional)
Edit Custom secondary user authentication message to be displayed to the user to change the text shown in the login pop-up.
4
Exclude specific users or groups (optional)
Exclude from secondary authentication - enter user names separated by semicolons (for example user1;user2;user3) to exempt them.
Exclude Active Directory user groups from secondary user authentication - enter group names in domain_name\group_name format, separated by semicolons, to exempt entire AD groups.
5
Save
Click Finish.
On Windows Server 2003, the computer must be restarted after enabling or disabling this option. On other Windows versions, it takes effect immediately.
The Two-Factor and Secondary Authentication section on a Windows Client.
The Client displays a Secondary User Authentication window. Enter the credentials of a Syteca user with the Access to Endpoint via Secondary Auth. permission for this Client.
3
Access is granted or denied
The credentials are validated against the Application Server. If the permission and credentials are correct, access is granted; otherwise the user sees a message that they lack the required permission.
4
Recording starts under the secondary identity
Once logged in, the Client records the session under <Windows account> (<secondary user name>) in the Activity Monitoring page’s User Name column.
Secondary user authentication on Linux applies when multiple people share a Terminal account (commonly root). The user enters additional credentials when they launch the Terminal, and the secondary user name is shown in brackets after the primary account name in the Client Sessions list.
Log in to the Management Tool as a user with the Client Configuration Management permission. Click Clients, then find the Linux Client or Client group and click its name.
2
Enable the option
On the Editing Client (or Editing Client Group) page, select the Authentication Options tab, scroll to Two-Factor and Secondary Authentication, and select Enable secondary user authentication on login.
3
Customize the login message (optional)
Edit Custom secondary user authentication message to be displayed to the user to change the text shown at the terminal prompt.
4
Exclude specific users (optional)
Exclude from secondary authentication - user names separated by semicolons.
Exclude secondary user authentication for inline SSH sessions - user names separated by semicolons, for sessions that shouldn’t require secondary credentials over inline SSH.
5
Save
Click Finish. The setting takes effect immediately - the next time any user on that Client (or Client group) opens a Terminal, they’re prompted for secondary credentials.
The Two-Factor and Secondary Authentication section on a Linux Client, including the inline SSH exclusion field.
The credentials are checked against the Application Server. With the right permission and correct credentials, the terminal opens; otherwise, the user sees an access-denied message.
5
Recording starts under the secondary identity
Once logged in, the Client records the session under <Linux user> (<secondary authentication user>) in the Client Sessions list’s User name column.