fitgap

UserLock

Features
Ease of use
Ease of management
Quality of support
Affordability
Market presence
Take the quiz to check if UserLock and its alternatives fit your requirements.
Pricing from
Pay-as-you-go
Free Trial
Free version unavailable
User corporate size
Small
Medium
Large
User industry
  1. Construction
  2. Agriculture, fishing, and forestry
  3. Manufacturing

What is UserLock

UserLock is an on-premises security tool for Microsoft Active Directory that adds multi-factor authentication and access controls to Windows logons, RDP sessions, IIS applications, and VPN connections using AD credentials. It targets IT and security teams that need to strengthen authentication and enforce session policies without replacing AD. The product focuses on controlling who can log on, from where, and how many sessions are allowed, and it provides auditing and alerting around AD user activity.

pros

Deep Active Directory integration

UserLock works directly with Microsoft Active Directory and Windows authentication flows, which reduces the need to deploy a separate identity store. It supports enforcing controls on common AD-backed access paths such as workstation logon and Remote Desktop. This approach fits organizations that want to harden AD authentication rather than migrate to a new IAM platform.

Granular access and session controls

The product enforces policies such as restricting logons by machine, time, and location, and limiting concurrent sessions per user. These controls help reduce account sharing and limit lateral movement opportunities when credentials are compromised. It also supports alerting on suspicious or non-compliant logon behavior for operational response.

On-premises deployment option

UserLock is designed for on-premises environments, which can align with organizations that have data residency or network isolation requirements. It can be deployed within existing Windows infrastructure and managed by administrators familiar with AD. This can be advantageous where cloud-first identity services are not feasible or not desired.

cons

Primarily AD-centric scope

UserLock’s core value depends on Microsoft Active Directory and Windows-based authentication scenarios. Organizations with significant non-AD identity sources or cloud-native application stacks may need additional tools for broader IAM coverage. It is not a full identity governance suite (e.g., lifecycle provisioning, certification workflows) on its own.

Limited endpoint management breadth

While it can influence endpoint access through logon controls, it is not a full endpoint management/RMM platform with software deployment, patching, inventory, and remote support capabilities. Teams looking for unified endpoint operations typically require separate endpoint management tooling. This can increase tool sprawl for MSP-style or large-scale endpoint operations.

PAM features are not comprehensive

UserLock can help reduce privileged account risk via stronger authentication and tighter logon policies, but it is not a complete privileged access management system. Capabilities such as privileged session recording, just-in-time elevation workflows, and vaulting/rotation of privileged credentials are typically outside its primary scope. Organizations with mature PAM requirements may need dedicated PAM tooling alongside it.

Plan & Pricing

Pricing model: Per-user subscription (licensed by number of active users in the previous 30 days).

Public pricing (example shown on official site): $1.60 per user, per month (example rate displayed for 100 users on a 3‑year billing term; price is shown as "per user, per month billed every 3 years").

Billing terms & discounts (as presented): 1‑year and 3‑year subscription options are shown; the 3‑year option indicates a "Save 20%" discount versus shorter terms.

How users are counted: Active user = any user that connects to the machines/servers audited by the UserLock micro-agent within a 30‑day period (site text).

What is included in subscription licenses (summary from official page): MFA for Windows machines (Windows login, VPN, IIS, SaaS, RDP/Remote Desktop, UAC), multiple MFA methods (UserLock Push, authenticator apps, USB security keys, recovery codes), SSO support, granular/context-based access policies, concurrent session restrictions, access activity monitoring, alerts & remote response, reporting, integrations (PowerShell, API), and support.

Purchase / quoting: The vendor asks customers to "Get a quote" or "Fill out the form" for a personalized quote; a public example price is shown but specific pricing for other quantities/terms requires a quote.

Other notes (from official site): MSP/MSSP options and multi‑site considerations are referenced; contact/sales phone numbers are provided on the site.

Seller details

IS Decisions
Biarritz, France
2000
Private
https://www.isdecisions.com/
https://x.com/isdecisions
https://www.linkedin.com/company/is-decisions/

Tools by IS Decisions

UserLock

Popular categories

All categories