Unique Customization Options Available with Access Director

Access Director is a powerful tool for Windows that allows managers and users to control specifically the amount of access and freedom that accounts have on the operating system. This is an incredibly powerful and useful system, but as we will see in a moment it is also very dynamic and versatile with a wide range of customization options that significantly increase security and reduce overheads.

What is Access Director and Why Should You Care?

Continue reading

Access Director Language Packs

Access Director Enterprise language packs let you to take advantage of the Multilingual User Interface.
A language file is a set of language-specific resource files that can be added to any version of Access Director Enterprise.

All language packs can be configured using your existing Group Policy Administrative Template (ADMx) or using registry entry with your package.

Released language packs:

Continue reading

Access Director Enterprise Reporting Point 3.9.1 Released

Access Director Enterprise Reporting Point 3.9.1 Released

Based on great  input, we have reviewed and added lots of new features in the reporting point

Reporting Point updates:

  • Added “needle” search for Software in Reporting page
  • Added Device page with the possibility to review verbose log files from clients
  • Added Active users and computers in Status page
  • Added Data Export to CSV or full file in the Settings page
  • Added updates to Reporting Point Authentication
  • Added optional Update Base URL in the settings page
  • Added Automatic Update interval in the settings page
  • Added JSON API using an API Key (see: Access Director Enterprise Reporting Point API)

Do you have a feature request? Don’t hesitate to contact us!

Access Director Enterprise Reporting Point API

In order to utilize the new API use following syntax:

https://<yourserver>/accessdirector/api.php?api_key=[api_key]&type=[type]

[api_key] should be equal to the generated public key (see above)

Also optional days parameter can be specified: https://<<yourserver>/accessdirector/api.php?api_key=[api_key]&type=[type]&days=[days]

If days parameter is specified then statistics data will be queried for the specified latest number of days

In case days parameter is omitted, we use default number of days: 90

The [type] may be equal to following values:

  • elevations_number
    Number of elevations was done within specified number of days
  • top_users
    Top 10 users who have elevated within specified number of days
  • apps_added_elevated_number
    Number of Applications Add (when user was elevated) within the last specified number of days
  • apps_added_not_elevated_number
    Number of Applications Add (when user was not elevated) within the last specified number of days
  • apps_removed_elevated_number
    Number of Applications Remove (when user was elevated) within the last specified number of days
  • apps_removed_not_elevated_number
    Number of Applications Remove (when user was not elevated) within the last specified number of days
  • active_computers_numberbr
    Number of computers that were active for latest specified number of days
  • active_users_number
    Number of users that were active for latest specified number of days
  • elevations_list
    List of elevated users was done within specified number of days
  • top_users_list
    Top users who have elevated within specified number of days
  • apps_added_elevated_list
    List of applications added (when user was elevated) within the last specified number of days
  • apps_added_not_elevated_list
    List of applications added (when user was not elevated) within the last specified number of days
  • apps_removed_elevated_list
    List of applications removed (when user was elevated) within the last specified number of days
  • apps_removed_not_elevated_list
    List of applications removed (when user was not elevated) within the last specified number of days
  • active_computers_list
    List of computers that were active for latest specified number of days
  • active_users_list
    List of users that were active for latest specified number of days

Access Director Enterprise 5.3.1 has been released

Access Director Enterprise 5.3.1 has been released!

Client Updates:

  • Added thread safe logic for all processing
  • Added support for HTTP & HTTPS link in “Reason for elevation” dialog
  • Added support for sending verbose log files for multiple users on the same machine
  • Added support for non-Unicode characters in some scenarios
  • The revised logic for Active Directory Connectors
  • New language packs available
    • Arabic, Bulgarian, Croatian, Czech, Dutch, Estonian, Finnish, French, German, Greek, Hebrew, Hungarian, Italian, Japanese, Korean, Latvian, Lithuanian, Norwegian, Polish, Portuguese (Brazil), Portuguese (Portugal), Romanian, Serbian (Latin), Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Thai, Traditional Chinese (Hong Kong), Traditional Chinese (Taiwan), Turkish, Ukrainian.

Do you have a feature request? Don’t hesitate to contact us!

Access Director – Certificate Warning

Certificate expire warning for Access Director version 2.5.
Access Director 2.5 will expire on 03/04/2018

Keep in mind, the version 2.5 is from 2014.
A lot of changes and fixes has been added since.

Also a critical security errors has been mitigated.

How can you check if your version has is expiring?

1. Browse to your installation directory – usually: C:\Program Files (x86)\Access Director
2. Right Click AccessDirectorTray.exe or AccessDirectorFramework.exe
3. Click the tab Digital Signatures
4. Click Details
5. Click View Certificate

If you see a Valid from: 29-01-2015 to 03-04-2018.  – Your version will expire!

Access Director Enterprise – Feature Update November 2017

It is now easier then ever to deploy Access Director Enterprise.
Based on input from IT-Pros we have added a standard package that removes added local administrators on first install.
This gives you are nice and clean baseline to work from.

Ready, Set, Go! Only your group policy-based changes to the local administrator’s group will be effective, all manually added users will be removed.

NOTE: if your using Group Policies to add specific users or groups to the local administrator’s group, these will still be refreshed and added.

Get input or feature requests? Let us know!

Access Director Enterprise Features

The main features includes the following topics:

Active Directory Integration
– Check and allows to elevated user, only if user is member for specific group.
– Checks if user is set as Owner on the computer object. Can be combined with User group or stand-alone.
– Supports caching of ldap data, for offline usage.

Central Reporting
– Send all information to intranet or internet based reporting point.

Easy Administration
– Little to non-administration using Active Directory or stand-alone

Customizable Elevation Timer
– Change the elevation timer to a time you see fit.

Group Policy ADMx Templates
– All configurations can be set using Group Policy ADMx template

Monitor Elevated Files
– Monitor what files are elevated on client computers

Monitor Installed Software
– Monitor the installed software on client computers
– Specific monitor for software installed during elevation timer and outside of elevated timer window

Monitor Uninstalled Software
– Monitor software uninstalled when the user is elevated or outside of elevated timer window

Pin-Code OTE (One-Time-Elevation)
– Require user to enter pin-code generated by 3.party application or service desk

Status reporting & logging
– Monitor What, Why, When and Where in one simplified web console

Supported versions: Access Director Supported versions
Changelog: Access Director Changelog

Easy Click Assistant 1.1 has been released

Easy Click Assistant has just been released in version 1.1

Updates now include:

  • Signed binaries
  • Support for parsing pre-defined commands to service (runs as system)
  • Support for parsing pre-defined commands to tray icon (runs as the user)
  • Support for multiple commands in one task, without requiring a full script.

Registry paths:

  • HKEY_LOCAL_MACHINE\SOFTWARE\Basic Bytes\
    • HKEY_LOCAL_MACHINE\SOFTWARE\Basic Bytes\Easy Click Assistant (Key)
      • Subcategory (REG_SZ)
        • 1, 2 or 3
    • Name of submenu (Example: Active Directory)
      • Computer (Key)
        • Name of task (Example: Policy Update Computer) (REG_SZ)
          • Command to execute: gpupdate /target:computer
      • User (Key)
        • Name of task (Example: Policy Update user) (REG_SZ)
          • Command to execute: gpupdate /target:user

User actions are executed in user context as the user (by the tray icon)
Computer actions are executed in system context as the local system (by the service)