SystoLOCK eliminates passwords and uses advanced cryptography and digital certificates to achieve an unprecedented level of security. Designed for on-premises use, SystoLOCK is also compatible with most cloud services.
SystoLOCK is one of the most innovative products on the market!
Why choose SystoLOCK?
SystoLOCK combines most sought after aspects: modern security, versatility, user friendliness, ease of use and administrative flexibility
Passwordless MFA
SystoLOCK is designed to support all Windows resources in your organization. It covers all Active Directory logins without extending the schema and is fully compatible with Office 365.
Phishing resistance
SystoLOCK supports phishing-resistant tokens that eliminate the risk of new multi-factor credentials being compromised by adversaries who may be eavesdropping on your infrastructure.
You are in control
Administrators can centrally configure all aspects of the platform: who, where and how can use SystoLOCK, including self-service. When authenticating to Entra ID, users use their local passwordless identities, with no credentials travelling to the cloud.
Highly available on-prem product
SystoLOCK does not rely on any cloud instances and is installed locally within your normal network infrastructure. It is intrinsically highly available, just as your domain controllers, and is designed to work non-stop.
Passwordless MFA for all logins
SystoLOCK does not rely on passwords to authenticate users. In fact, it removes passwords from user accounts, making it impossible to compromise protected accounts through password-based attacks.
Across Active Directory and beyond
SystoLOCK does not stop at Active Directory: all cloud logins, federated with your on-premises AD are instantly covered by the new passwordless MFA and are also no longer phishable: users can authenticate in the cloud using local passwordless identities.
A variety of authentication means
You chose what to use for authentication: a smartphone, an OTP generator, an NFC card, a FIDO stick or may be a combination of those. Shared accounts? Not a problem for SystoLOCK. And self-service for automatic configuration is Included, too.
Highly available on-prem product
SystoLOCK does not rely on any cloud instances and is installed locally within your normal network infrastructure. It is intrinsically highly available, just as your domain controllers, and is designed to work non-stop.
Passwordless MFA for all logins
SystoLOCK does not rely on passwords to authenticate users. In fact, it removes passwords from user accounts, making it impossible to compromise protected accounts through password-based attacks.
Highly available on-prem product
SystoLOCK does not rely on any cloud instances and is installed locally within your normal network infrastructure. It is intrinsically highly available, just as your domain controllers, and is designed to work non-stop.
Passwordless MFA for all logins
SystoLOCK does not rely on passwords to authenticate users. In fact, it removes passwords from user accounts, making it impossible to compromise protected accounts through password-based attacks.
Across Active Directory and beyond
SystoLOCK does not stop at Active Directory: all cloud logins, federated with your on-premises AD are instantly covered by the new passwordless MFA and are also no longer phishable: users can authenticate in the cloud using local passwordless identities.
A variety of authentication means
You chose what to use for authentication: a smartphone, an OTP generator, an NFC card, a FIDO stick or may be a combination of those. Shared accounts? Not a problem for SystoLOCK. And self-service for automatic configuration is Included, too.
Highly available on-prem product
SystoLOCK does not rely on any cloud instances and is installed locally within your normal network infrastructure. It is intrinsically highly available, just as your domain controllers, and is designed to work non-stop.
Passwordless MFA for all logins
SystoLOCK does not rely on passwords to authenticate users. In fact, it removes passwords from user accounts, making it impossible to compromise protected accounts through password-based attacks.
High availability
SystoLOCK is intrinsically highly available, just like your domain controllers. Simply install extra instances of the server to ensure uninterrupted authentication flow. No configuration is needed.
Self-Service
Users can be enabled to self-configure their access via SystoLOCK and can also change their PIN or configure ActiveSync profiles on their mobile phones.
Compliance
SystoLOCK helps meeting the requirements of security standards such as NIS2 and DORA by protecting user accounts and corporate assets from authentication threats.
SystoLOCK Modules
SystoLOCK has components for every network node in your infrastructure
HTTP Proxy and Agent
A cloud service that provides inbound connectivity to authentication servers for the companion application without the need for perimeter port opening and a local service that registers with the proxy to provide inbound connectivity for the companion application.
Authentication Service
A highly available service that handles connections from different types of SystoLOCK clients, validating their credentials and requesting digital certificates on behalf of users. With PowerShell modules for setup, management and diagnostics.
Windows Client
The driver that runs on clients or servers that participate in the SystoLOCK infrastructure. Responsible for collecting credentials and providing advanced functionality such as diagnostics and self-service. Deploy-able with software distribution tools.
Management Tools
Typically installed on administrators' PCs and on SystoLOCK servers and implemented as an MMC snap-in and PowerShell module. Combined with an extension to the ADUC console, it provides a comprehensive management and monitoring solution for SystoLOCK.
Companion Mobile App
An advanced mobile authenticator that can automatically authenticate users to SystoLOCK servers and also generate OATH-compliant one-time passwords for general use.
VPN Client
Typically running on notebooks, SystoLOCK VPN Client can establish VPN connections using SystoLOCK credentials. Compatible with Microsoft VPN and Cisco AnyConnect.
SAML Identity Providers
Running on on-premises servers or inside Azure, SystoLOCK identity providers ensure compatibility with a wide range of web applications and authentication services that use SAML2, such as Office 365, Sales Force, etc.
RD Gateway, Web Plugins
A plugin that provides authentication for the Remote Desktop Gateway servers of RDP farms and an IIS module that injects authentication into the RDP files and provides compatibility with SystoLOCK authentication via an AD FS proxy.
RADIUS Plugin
Runs as a plugin for Microsoft Network Policy Server to facilitate VPN logins from almost any VPN gateway.
HTTP Proxy and Agent
A cloud service that provides inbound connectivity to authentication servers for the companion application without the need for perimeter port opening and a local service that registers with the proxy to provide inbound connectivity for the companion application.
Authentication Service
A highly available service that handles connections from different types of SystoLOCK clients, validating their credentials and requesting digital certificates on behalf of users. With PowerShell modules for setup, management and diagnostics.
Windows Client
The driver that runs on clients or servers that participate in the SystoLOCK infrastructure. Responsible for collecting credentials and providing advanced functionality such as diagnostics and self-service. Deploy-able with software distribution tools.
Management Tools
Typically installed on administrators' PCs and on SystoLOCK servers and implemented as an MMC snap-in and PowerShell module. Combined with an extension to the ADUC console, it provides a comprehensive management and monitoring solution for SystoLOCK.