Changelog
See the new features, improvements and bug fixes of UserLock.
September 23, 2026
Support FIDO2 authentication. Use FIDO2 USB and NFC keys, including biometric keys such as a fingerprint, with a reinforced PIN request.
Managing the UAC session type in the access policies "Session Limits", "Machine Restrictions" and "Time Restrictions".
Connect any OIDC-compatible SaaS app to UserLock SSO via a custom plugin.
SSO for Zoom, OpenAI, and Snowflake.
Find anything faster with global search.
Certificate-based security capabilities to strengthen trust across on-premises and remote access: UserLock SSO now enables passwordless sign-in to SaaS applications when MFA is required, with a trusted user certificate, mapped to an Active Directory account, as the first factor and UserLock MFA as the second; UserLock Anywhere now supports client (machine) certificate authentication as a modern alternative to NTLM.
The default database is now SQLite (and no longer Microsoft Access).
Configure SSO directly in the configuration wizard.
Removal of requirements for Remote Registry, Ping, or SMB access (install the UserLock agent on client machines using the MSI package).
Clone policies across any entity type.
More language support, now available in German, Dutch, Portuguese, and Arabic. This comes on top of Spanish, Japanese, English, and French.
Trying to modify a server setting with a wrong value leads to an incorrect record for the admin action result.
Effective access policies do not display "SaaS" and "UAC" (policy "Session limits") if these policies are configured.
In the case of insufficient privileges for User Account Control (UAC), two events are recorded in the database: success and failure.
Report logos configured in the desktop console do not appear in the web console ("Server settings" > "Reporting").
The agent service stops and displays an "Assertion failed" pop-up window on a machine where the server is not responding to the stream pipe.
An IIS logoff event may be inserted into the backup server database with missing or incorrect data.
September 29, 2026
Incorrect data will be displayed if you use a filter for "User domain" in "Is not" mode.
MFA configuration skipped events do not appear in reports for SaaS session events.
It may happen that the display name of a group in a subdomain or sibling domain displays the domain name along with "%5" instead of "\".
The OU display name appears URL-encoded in access policies when it contains special characters.
In the configuration wizard, a white screen appears on the protected zone page while information is being retrieved.
User account sessions with the same username but from different forests are marked as simultaneous.
The work hours report fails with a 500 error ("Missing operand after ... operator") when the user account name contains an apostrophe.
If a header or footer logo is configured on the legacy console and its path is inaccessible, the Excel export of the report will fail.
When an operator who does not have the "User sessions" permission opens the details of an entity (user, group, or organizational unit), the "Permission denied" page is displayed with a dark gray bar.
When an RDP session is active and is joined from the target computer's console without first locking it, a subsequent lock event is not recorded in the database, and the session history displays several incorrect data points.
The pre-filled values for the "Source or target machine name" filter consistently fail with MS Access databases.
Exporting reports to Excel or CSV format fails when events contain empty machine or client names.
If the license is user-based and license consumption exceeds the maximum allowed, an SSO login attempt by a user included in the license is denied.
Exporting large PDF reports fails, but the operation is recorded as successful.
PDF generation crashes well below the documented limit of 20,000 lines.
In historical type reports, when an LDAP-based filter (LDAP group, organizational unit users, organizational unit computers) is combined with a user, domain, or machine filter, in AND mode, the results are broadened instead of narrowed.
In the configuration wizard, the "Strict mode" setting in the protected zone configuration step is not retained if the wizard is reopened.
Reports crash with the error "Cannot read properties of null (reading 'length')" when "ComputerName" is NULL in the database.
When an environment contains many elements and the protected zone is configured for a large number of OUs with at least one OU excluded, some machines are missing from the Environment view.
July 23, 2026
If you have configured many SSO profiles, the last profile added is not saved and is lost after an UserLockSSO service restart.
If you have made changes to the SSL binding for SSO and you update the SSL certificate, the changes to the SSL binding are not retained.
After switching from the default database (MS Access) to an SQL Server database using SQL authentication or to MySQL, the database information fields are empty.
The read-only database connection test fails for SQL Server and MySQL ("serverName" and "databaseName" are null).
It is impossible to enroll MFA with USB Token2 (HOTP) keys because they are not detected.
When enrolling in MFA via MFA IIS, if TOTP is the only available enrollment method and recovery codes are enabled, after TOTP enrollment the recovery codes are not displayed.
During an unlock or reconnection event, the pop-up window for the "Warn end user in real time" function displays "Logon" instead of "Unlock" or "Connection".
A driver that registers the keyboard interface in exclusive mode blocks the detection of a YubiKey.
On the graphical interface of a standalone UserLock server, it is not possible to save advanced settings because of the value of -1 for the advanced setting "NetBIOS interface".
In the "Environment", "Users", "All users" view, the button to access the last page does not work.
Push and Relay URLs are retrieved from a backup server even if the corresponding options are not enabled.
In the server properties, under "Database", with "Connection string" mode selected, custom connection string settings are lost during saving and reloading.
The "How to fix" messages do not appear when needed.
An exception is generated when starting the legacy console.
In a time zone with an obsolete alias, attempting to add a new scheduled report results in an unexpected error.
If the task manager is enabled and an unexpected exception occurs while logging on, unlocking, or reconnecting, the task manager is not enabled after this session event.
Under Windows Server Core, the CMD command prompt does not run when logging in.
In the scheduling wizard of the "Event timeline" report, when attempting to select a view other than "All events", nothing happens.
The warning about a view linked to a scheduled report is not displaying correctly.
When attempting to delete a view that you created and that is part of a scheduled report, nothing happens when you click on "View scheduled reports".
Under Windows 11, a user who has never logged into the machine gets a black screen instead of seeing the MFA enrolment window.
The message related to the resolution of the MFA help request is displayed twice.
When the SSO service starts, if the current configuration file is incorrect, the service does not retrieve the last valid configuration file and does not start.
Entity verification does not have a fallback solution if the UserLockHelperService is stopped.
A view saved as private or shared with specific users is displayed to other users.
April 21, 2026
A connection via RDP causes the "Warn end user in real time" feature popup to appear in the current session.
In the details of an access policy entity (user, group, OU), vertical scrolling is blocked even if there is only one item (which does not require horizontal scrolling).
Time zone management is incorrect in the start date of tasks scheduled in a time zone subject to summer time.
Opening the actions of a machine generates an error.
With an Access database, for the "Session history" report, no results are listed when the "Group by" function is used.
In "Environment", "Machines", the "Installed agents" indicator is not updated after deploying the desktop agent on a machine.
It is not possible to configure a backup SSO service.
On a UserLock server of the Standalone terminal server type, in the "Popup" section of "Alerts and notifications", it is not possible to configure a machine name.
When LDAP search is used in a dialog box, scrolling via the mouse wheel does not work in the drop-down list of results.
In "Machine Restrictions", it is not possible to define multiple rules per IP address ranges or there is latency.
When you reset a session from the "Activity" view, the selected session disappears but the "1 item selected" indicator remains displayed.
In "Environment", "Machines", "All machines" tab, the column names "Operating system" and "Operating system version" are not translated (always displayed in English).
In the web console, when an IIS session is administratively closed, the page does not update once the action is performed.
The "Radius wired" and "Radius generic" session types are displayed in GUI in "Machine restrictions", "Hour restrictions" and "Time quota".
If geolocation is enabled and the "Allow connections from Proxy servers" option is enabled, then a connection from a proxy is refused instead of being allowed.
Changing the password will not work if the "CheckUserLockFirst" feature is not enabled (bug introduced in UserLock 13.0.0.119).
Problems with quick search in Active Directory pages.
The Token2 enrolment dialog box appears if the user selects "USB Token" and no USB key is inserted.
In primary and backup UserLock 12.1 (or lower) installations, after upgrading the primary server to 12.2 (or higher) and before upgrading the backup server, MFA is automatically reset upon a login event.
Some administrative actions remain in a pending state.
Resetting the MFA key via UserLockPowerShell, UserLockAPI or ULTERM with an invalid username generates an entry in "Administrators actions".
The display of effective access policies does not correctly reflect the policy applied in the mode chosen for "Access policy conflicts resolution".
Disabling a scheduled report in the web application does not disable it in the UserLock console.
A scheduled report sends an email with an incorrect URL and data period.
When entering a recipient in the "To:" field for sending a scheduled report by email, this same entry is automatically transferred to the "Cc:", "Bcc:" and "Email subject" fields.
The configuration GUID changes every 2 hours.
Filter search is not working.
After upgrading from version V11 or V12 to version V13, when viewing the "Database" section of the settings, an exception may occur and prevent the modification of the settings.
In the configuration wizard, SSO configuration form, clicking "Learn more" validates the SSO configuration.
After creating a temporary access policy (without a pre-existing permanent policy) and defining restrictions of type "Multi-factor authentication", "Machine restrictions", "Hour restrictions" or "Time quota", modifying the period of the temporary access policy generates an error.
Error 87 on the SNI list can occur on the UserLock console's SSO page in certain environments.
When the primary service is stopped, the IIS Push MFA notification is never received.
From the console of a backup server, attempting to launch a machine action for a machine in the protected zone indicates that the machine is outside the protected zone.
If you install single sign-on (SSO) on a server whose display language is French, the setup wizard will not be able to detect or validate the SSL certificate selected for single sign-on.
Protected user accounts in the remote forest are deleted if no domain controller is available when the service starts.
After scheduling the "MFA events" report and/or the "Denied logons" report, the 404 page is displayed if you try to view the report from the scheduled reports page.
The UserLock service may not stop properly when the server is shut down.
March 6, 2026
Updated .NET from version 8.0.6 to version 8.0.22.
NIST servers are no longer used for time verification (only Google servers are now used).
The ADMX and ADM files have been modified to allow empty content for the "Public URL to the UserLock Anywhere HTTP Proxy" field.
The desktop agent is uninstalled with the NetBIOS name instead of the FQDN.
MFA is required after an invalid password.
SSO - Error during configuration in the UserLock configuration wizard.
Unexpected behavior of the desktop agent due to the absence of some string resources in Japanese, Portuguese, German, Dutch, Spanish, and Arabic.
There is a memory leak when the UserLock service treats many logon commands.
Each SSO logout results in an error.
The "Without agent" default view of the "Machines" page in the "Environment" section does not display agentless machines.
A logon denied by Windows, received via UserLock Anywhere in delegation mode, generates an entry with an unnamed computer.
After restarting, a machine connected to AnyWhere cloud can apply "Logons without UserLock connection" (instead of using AnyWhere cloud).
The "Reset the MFA config" action is disabled for non-audited users.
In a Japanese OS, the UserLock uninstallation dialog box displays incomprehensible characters.
The "Country" column and associated filter are missing in Activity > Active Sessions page.
Non-functional machine links in Admin Actions panel.
There is no link for entity name in AD Environment pages (All machines, All users, Groups, OUs) to open detail view from the selected row.
Negative consumed time quotas may be displayed when carry-over is enabled, and resetting the time consumed to zero does not work.
The legacy agent station technology is used when connecting with a local account on a Standalone UserLock server.
If the MFA key reset via the backup UserLock server is performed while the primary UserLock server is down, an MFA request is made instead of an MFA enrollment when the primary server is operational again.
The evaluation license may be marked as "expired" if it is installed in time zones with a negative time offset from UTC.
The "Simultaneous session history" report does not display a sub-table for a listed user with simultaneous sessions.
If you install version 13.0 of the desktop agent MSI and version 12.2 or earlier of the desktop agent MSI is already installed, you will see two desktop agent MSI installations.
In the access policy wizard, the information about target containers does not allow them to be distinguished in tiered AD environments.
An attempt to update the agent on a computer connected via VPN may fail with error 53 even though the target machine's FQDN is reachable.
Problems encountered when launching an administrative shutdown of a machine from the "Machines" page of the "Environment" section.
October 29, 2025
Custom credential provider for Windows Hello PIN, improving the MFA experience and security.
Custom credential provider for Pre-Logon Access Provider (PLAP), improving the MFA experience and security.
Windows Server 2025 RemoteApp connections now use the custom credential provider, improving the MFA experience and security.
Reporting management for logon denied events with User Account Control (UAC) session type.
Remote agent communication with UserLock over the Internet, without VPN or IIS server.
Certificate authentication for UserLock Anywhere.
Client certificate verification for UserLock SSO.
New interface with reorganized sections: Dashboard, Environment, Access Policies, Activity, Reporting, and Server settings.
Pages displaying all Active Directory entities (machines, users, groups, OUs) with AD attributes, navigation links, and statistics.
Dedicated dashboards for each entity (user, machine, group, OU) showing activity, applied policies, and filtered reports.
Dedicated pages and step-by-step wizard for each access policy type (MFA, time, machine restrictions, etc.).
Custom views system available on all pages (filters, columns, sorting) with save and share options.
Admin actions panel tracking ongoing and completed administrative operations in real time.
Reports for admin actions and configuration changes ensuring complete audit traceability.
Spanish and Japanese language interfaces added.
The custom credential provider now wraps around the Windows credential provider.
The mechanism of the "Close previous session" feature of the credential provider has been improved.
The mechanism of the "Logons without UserLock connection" feature of the credential provider has been improved.
Improved recovery codes and rate-limiting mechanisms.
Terminology and labels revised for better alignment with Active Directory and administrator workflows.
Clearer, task-oriented navigation structure.
Simplified access policy editor with inline explanations and easier policy management.
Redesigned reporting with new charts, instant display, and improved performance.
Enhanced report scheduler with direct-link delivery by email.
Server settings reorganized for faster access and clearer layout.
Unified interface and behavior across web and desktop consoles.
MFA is no longer prompted before password changes.
The Wi-Fi session reset database records have "VPN" as the session type.
Timeout issues in the credential provider.
The behaviors for the "Ask for MFA" and "Force MFA" configurations of the "Logons without UserLock connection" feature are not correct in the credential provider.