Problem overview
This automation addresses urgent security risks by swiftly locking down endpoints, preventing unauthorized access, and stopping potential threats. When a device is compromised or at risk, it’s crucial to secure it remotely and immediately.
When triggered—either manually or by adding the “Lock” tag—the automation terminates all current sessions and disables user accounts across Windows, macOS, and Linux endpoints. It ensures that no new logins can occur while still allowing Level to maintain remote management capabilities. If a Windows device is part of a domain, the automation additionally locks all relevant Active Directory accounts for complete coverage. When the automation can’t fully lock a device, it automatically generates an alert, allowing prompt intervention.
Use cases
- Immediate lock-down of lost or stolen endpoints
- Rapid response to suspicious activity
- Automatic lock triggered by policy or security event
- Enforcing compliance for devices in high-risk environments
Recommendations
- Test Before Production: Run the automation on a non-critical device to confirm successful lock without disrupting operations.
- Preemptive Setup: Have the “Unlock” automation ready so you can reverse changes once the threat is cleared or the situation is resolved.
- Review Account Dependencies: Ensure critical services won’t be impacted by disabled local accounts.
- Monitor Alerts: Pay attention to any alert notifications if the lock cannot be fully executed.