You're using a temporary or default password. You must set a new one before continuing.
System Utility
—
Device
User
Public IP
VPN
Agent
Last Seen
Status
IP Address
Description
Status
Policy Settings
Every field below is live — saved changes are versioned (see history below)
and take effect on each agent's next check-in automatically, no separate
push step or agent restart required.
Check Interval (seconds)
VPN Required for Remote Users
Internet Block Enabled
Server-Outage Cache Validity (hours)
VPN Connect Grace Timer (minutes)
OTP Validity (minutes)
Maintenance Mode Duration (minutes)
Max Temporary Access Duration (minutes)
Max Emergency Access Duration (minutes)
OTP Notification Emails
VPN Client Profiles
The device tries each ENABLED profile below, in order, and launches whichever one's executable it actually finds installed on that machine when someone clicks "Connect VPN Now" -- no selection is ever needed on the user's side. Add one entry per VPN client your organization uses (e.g. Sophos Connect, SonicWall NetExtender). "Trusted Program" is optional and separate from the launch command -- set it only if the VPN client's actual background connecting process is a different executable than the one people click to open it; that trusted program is allowed to reach any destination while a device is blocked.
Order
Name
Launch Command
Trusted Program
Enabled
VPN Gateway Allow-List
Always allowed through the firewall even while a device is blocked. The agent already allows common VPN ports (IKE, IPsec, OpenVPN, WireGuard, standard SSL-VPN 443) automatically -- only add an entry here if your VPN gateway uses a non-standard port. Two entry formats: "host:port" allows only that specific destination (narrow, recommended for normal use). A bare port number (e.g. "8443") allows that port to any destination -- more permissive, useful when a VPN gateway rotates through many/unknown backend IPs, but be aware it means anything on the internet using that port becomes reachable while blocked, not just your VPN. Use bare-port entries deliberately, not as a default.
VPN Egress IP Ranges
Optional, but the strongest available VPN-connected signal when set: if a device's actual public IP falls in one of these ranges, it's trusted as VPN-connected directly, without relying on local adapter/connection detection (which can be unreliable for some third-party VPN clients). Find your VPN gateway's egress range from your network team if you have one, or leave blank to rely on adapter detection alone.
Enforcement Mode
Full Block is the strongest guarantee: nothing gets through except what's explicitly allowed. Web Traffic Only blocks web browsing by port (80/443) -- meaningfully weaker, and only safe if your VPN gateway does NOT also use port 443, since Windows Firewall's rule precedence cannot reliably guarantee a narrow allow-exception overrides a broader block on the same port; the agent tests its own connection to this management server immediately after switching and automatically reverts if that connection is lost. Browser Block avoids that port conflict entirely by blocking specific browser applications (Chrome, Edge, Firefox, etc.) by their exact program identity instead of by port -- the management server, VPN client, antivirus, and every other application are completely unaffected regardless of what port they use, since a Block rule scoped to a browser's exact executable path never competes with anything else.
Blocked Browser Applications
Only used by Browser Block mode above. Executable filenames to block (e.g. "chrome.exe", "msedge.exe") -- the agent finds each one's actual installed path on every machine automatically, so this list doesn't need to include paths. Leave blank to use the built-in default list (Chrome, Edge, Firefox, Brave, Opera, Internet Explorer); add others here (e.g. an internal or legacy browser) if your organization uses one not in that list.
Terminate Existing Connections on Block
Aggressive -- understand this before enabling. Windows Firewall only blocks new outbound connections; it does not close connections that were already open before blocking began (e.g. browser tabs opened just before the grace timer expired can keep working indefinitely otherwise). Enabling this closes the entire application that owns any such connection the moment blocking starts -- e.g. the user's whole browser, not just that one tab. Core Windows system processes are never touched regardless of this setting. Only applies in Full Block mode. Off by default; enable deliberately if you need blocking to take effect immediately rather than only for new connections going forward.
Notification Message
Version History
Version
Changed By
When
Grace
Check Interval
When a device goes remote without VPN, it gets one grace window per calendar day
with a visible countdown and unblocked access before enforcement blocks it — once
VPN connects successfully that day, later disconnects/reconnects, Wi-Fi changes,
sleep, or reboot do not grant a second window; enforcement resumes immediately
until the next day. Maintenance OTPs are generated per-device from the Devices tab
and are only ever delivered by email — never shown in this console.
SMTP Configuration
This account sends every system email: login verification codes, admin invitations,
temporary-access and maintenance OTP notifications, password-reset notices, Emergency
Access alerts, and future notifications. Most providers (Office 365, Zoho, Gmail)
require an app-specific password here rather than your normal
mailbox password.
SMTP Server / Host
SMTP Port
Encryption
SMTP Username
SMTP Password
From Email Address
From Display Name
Time
Actor
Action
Target
Details
A controlled, always-expiring exception for a broad VPN outage — scoped to a single device,
a single user's devices, or every device in the organization. This is not a
permanent whitelist: every grant has a hard expiry, requires a stated reason, and is fully
audited. Configured recipients (Policy Settings → SMTP notification list) are emailed when
a grant is created.
Scope
Reason
Granted By
Expires
Status
Push signed Windows Desktop Agent installers to devices. Updates install silently — no wizard,
no prompts — and apply automatically on the device's next check-in, including devices that are
currently offline (their job simply stays pending until they reconnect). VPN enforcement continues
uninterrupted during the update; a failed install reports back and does not change the device's
recorded version.
Releases
Version
Type
Min Windows
Signed
Size
Uploaded By
Uploaded
Update History
Device
From → To
Status
Initiated By
Created
Last Attempt
Result / Failure Reason
Session history and audit trail for Remote Support access. The user generates a code
themselves from their status window and reads it to whoever they're talking to -- entering
it below connects immediately, since sharing the code is what they're consenting to.
Device
User
Requested By
Reason
Duration
Status
Created
Ended
Result
Name
Email
Role
MFA
Status
Last Login
Pending Invitations
Email
Role
Expires
Create Admin User
A temporary password will be generated and emailed. They'll be required to set a new one on first login.
Invite Admin User
They'll receive an email with a link to set up their own password (valid 72 hours).
Device
Actions
Agent Update
Remote Support
Temporary Access History
Reason
Duration
Authorized By
Scheduled
Status
Generate Temporary Access
The OTP is emailed to the addresses configured under Policy Settings — never shown here. Relay it to the user/technician over a trusted channel.
Grant Emergency Access
This takes effect immediately — no OTP entry needed on the device. It expires automatically;
you can also revoke it early from this tab. An explicit device Block always overrides this.
Upload New Agent Version
The server computes and stores the file's SHA-256 automatically regardless. If you paste a checksum
here too, a mismatch is rejected outright rather than silently trusting it. The file is also checked
for the presence of an Authenticode signature block — this confirms something is signed, not that the
signature is valid or trusted; the agent performs the real cryptographic check before installing.
Push Agent Update
Devices already on this version, or that already have an update in progress, are automatically
skipped. Offline devices still get a job — it stays pending and installs the next time they check in.
Connect with Remote Support Code
The user generates this code themselves from their status window and reads it to you.
Entering it here connects immediately -- there is no separate approval step on their side,
since sharing the code with you is what they're consenting to.
Remote Support Session
Device
—
User
—
Requested By
—
Connection
—
Time Remaining
—
Waiting for the agent's screen stream
This window has established the secure session and signaling connection. Live screen mirroring and
remote control require the Windows agent's screen-capture module, which is a separate piece of work
not yet built (see docs/REMOTE_SUPPORT.md) — this is not a bug, it's the current state of the feature.