UserLock 13.1 (beta): Release notes
UserLock 13.1 (beta) brings support for FIDO2 authentication, UAC session controls, policy cloning, plus a pile of things that make your job easier.
Updated September 23, 2026:quality(90))
UserLock 13.1 is now available to beta testers. Here's what's new and why you should test.
Test the beta
Become a beta tester and give feedback to help shape the general release.
Your YubiKey Bio series works with UserLock now. So do most other FIDO2-enabled USB and NFC security keys, including biometric authenticators that use a fingerprint with a reinforced PIN request.
Not supported for VPN (yet). Everything else: yes.
Manage UAC elevation prompts as a session type in UserLock. Apply working hours limits, machine restrictions, or authorization rules to limit the window for lateral movement. It stays invisible to end users so doesn't add friction.
Time quotas cannot be applied to UAC sessions (obviously).
Use any OIDC app with UserLock SSO. The custom plugin works exactly like it does for SAML apps. Zoom, OpenAI, and Snowflake are preconfigured for you (choose SAML or OIDC).
If a browser presents a valid machine or user certificate identifying an AD user and MFA is required, users can now go straight to MFA. There's no Windows password prompt. Where MFA isn't required, standard auth applies. This builds on the certificate-based capabilities in UserLock 13.0 and helps keep security lightweight and, well, secure.
(Non-domain-joined machines may still prompt for a password).
Configure a policy once. Clone it across your AD users, groups, or OUs. This makes it so much easier to set up and manage policies across your AD. It's possible because of the recent integration of AD with UserLock, and we wish it existed a long time ago.
Now the UserLock dashboard is available in German, Dutch, Portuguese, and Arabic. This comes in addition to the already availalbe Spanish, Japanese, English, and French.
There's a global search bar in UserLock now. No drilling through the tree. Search users, groups, policies, or machines and it appears immediately. Small thing, saves a lot of time.
Search by name (starts-with or contains) across multi-domain environments. Handles large AD trees, enterprise environments, and MSPs running multiple domains. Removes pain and may save hair.
The dashboard loads faster
Machine, user and active user lists are now exportable as PDFs directly from the console
SSO SAML certificate renewal moves into the setup wizard (faster, easier)
ProtectedZone loads step-by-step on large AD trees instead of stalling
Standalone server installs surface only the options relevant to that configuration
The default database is now SQLite (and no longer Microsoft Access).
Join the few, the proud, the ones who know that giving feedback helps us help you, faster.
:quality(90))
:quality(90))
:quality(90))