Q:
What can Viewfinity products offer your organization?
A: Viewfinity offers uncomplicated systems and privilege management solutions to manage, support and control desktops,
laptops and Windows servers. Viewfinity is a single platform used for supporting both on-network PCs and mobile users through
which IT administrators can manage and control any computer over the WAN regardless of worker location.
Viewfinity offers true native remote systems management capabilities with absolute network independence;
there is no reliance on corporate network connectivity or VPN.
We offer a better method for mobile workforce management for patch management, software and OS deployment,
manage user privileges, troubleshoot and resolve problems faster, and more. Viewfinity also complements traditional
systems management, like SCCM and SMS, by offering the ability to flexibly manage administrator rights for locked
down computers. The software is intuitive and easy to use, and no training is required.
Viewfinity systems and privilege management solution can be delivered from a cloud hosted platform or installed on premises.
Practical Features and Benefits of Viewfinity Systems and Privilege Management
- Deploys software using only an Internet connection, no server is required
- Reaches and supports mobile workers who are disconnected from corporate network
- Provides OS image deployment
- Supports locked down, least privileges environments with management of privileges through granular regulation
of administrator rights
- Centrally manages all laptops and desktops on the application-level, even if the machine is located outside the firewall
- Provides central management of securing and patching all systems in the organization
- Remote desktop capabilities connect to remote computers locally or through the secure HTTPS tunnel
- Asset management prepares for software audits, reconciles purchases and helps forecast future software license
needs based on real-time usage information
- Saves money through automated power management policies
Q:
How can your product help my organization maintain our PC lockdown policy for laptops and desktops?
A: Through the use of automated policy settings, corporate guidelines can be established and applied for multiple dimensions of configurable, logical groupings: departments, applications, end users, connectivity status, time of day and more. Our Viewfinity Privilege Management offers a rich set of features that help IT and Business Managers ensure their organization is operating within a least privileged environment and according to legal parameters of software license agreements. Our software helps you to automatically manage your Windows application control policies dictated by corporate management and your legal department.
The following features are available to help meet your corporate compliance and security needs:
- Application Lockdown: Ability to reset changes to the individual applications to corporate standard. Provides IT department with ability to set protection on critical applications which should not be updated even if user posses local administrative rights. If Viewfinity detects that application configuration files, registry setting, dlls, or executables for any of these protected applications are modified, Viewfinity will automatically rollback the application to its protected state.
- Block Application: Using Viewfinity, the IT Administrator may establish policies that identify applications (by group if needed) that should be blocked from executing on corporate desktops and laptops. For example, the Brokerage division has a specific policy that prohibits any Instant Messaging software form executing. Viewfinity automatically enforces this policy for members of the Brokerage group, ensuring that these PCs are intact with corporate compliance regulations. Policies can be set for multiple combinations software such as Skype, ICQ, Yahoo Messenger, AOL, etc. Policies can also be flagged to unblock usage of specific applications while the end user is not connected to the corporate network.
- Elevate Privileges Certain applications and desktop functions (ActiveX, application, and printer installations) require local administrative privileges in order to run and function properly on a desktop or laptop. Most organizations consider this practice to be a security risk. Viewfinity solves this problem by elevating security rights to administrative levels per specific process. There is no need to jeopardize your network by granting full administrative rights to users just so they can run a business application that requires administrative privileges
- Activity Recording: Our real-time monitoring and recording of laptop, desktop and application events provides the administrator with a auditable record of all changes being made on the laptop or desktop. Viewfinity's precise activity recording feature provides a picture of all meaningful user/application activity for every laptop and desktop in easy-to-identify format.
- Policy Management: Viewfinity's policy management provides built-in, preconfigured capabilities for granular application-level control and policy customization to help control your desktop environment. Many conditions that formerly required complete lockdown in order to be enforced can now be implemented without creating excessive limitations on the end user machine. Supports multiple configurable options, by department/groups, time of day, connectivity status and more.
- Policy Auditing & Reporting: To ensure compliance, Viewfinity has built-in audit reporting that provides automated confirmation of delivery and enforcement of policies. Viewfinity provides detailed reporting on all administrator privilege policies, including an audit trail report that provides confirmation that a policy has been delivered and activated on endpoint devices. This includes validation of policy delivery to mobile and remote users, single or group of computers and/or for a specific application.
Q:
My mobile users have local administrative rights. I cannot revoke admin rights but at the same time I would like
to know when they install non compliant software on their computers so I could take action. Is this possible with your product?
A: Viewfinity supports auto notification upon installation of specified applications. Administrators may create a policy containing a group of applications which are not in compliance with internal corporate policies and receive notifications if these applications are being installed or launched.
Q:
I have a group of users who have local administrative rights on their computers. They can install any
applications on their computers, which may create security issues for our network. How Viewfinity can help to address this issue?
A: There are several ways to address this problem. Viewfinity's Block Application
or Hide Application Policy can be enforced. For example, an Administrator can create group of
Instant Messenger Applications (AOL, ICQ, Skype, etc.) and block/hide execution of these applications
either permanently or based on time schedule/connectivity status/group.
Q:
I am running a locked down desktop environment. Granting local administrative rights is against company policy.
I have a specific group of users who need to run an application which requires local administrative rights in
order to run and execute specific functions. Can Viewfinity help me to preserve compliance on my desktops while
still allowing this group of users to run this application?
A: Yes. Any policy can be created to elevate privileges for applications requiring administrative rights and applied to groups of computers. There is no need to grant admin rights to the end users. Viewfinity will raise security rights only for the individual application requiring such privileges.
Q:
What other functions are available using the Privilege Management feature?
A: Viewfinity supports a variety of management functions for which privilege elevation can be applied.
Among these options are: Printer installations, Microsoft Management Console, Power Options,
ActiveX installation, Approval of certain application installations, and many others.
Q:
When Privilege Elevation technology is applied to certain a process, will the process execute under the credentials of the Administrator?
A: When permissions are raised, the elevation is performed directly within the security token of the user account. The application or process is started using the current user credentials as opposed to using RUN AS which needs the Administrative account in order to raise privileges.
The RUN AS method potentially introduces security risks if administrator's password is provided.
Q:
Do I need to logout in order for a Policy to be enforced?
A: No. Any Viewfinity policies, including Privilege Management, Lockdown, and Block are delivered in real time and do not require users to logoff/login in order to take effect.
Q:
If my clients are located outside of the corporate network and are not connected through a VPN, can I still deliver policies?
A: Yes. Polices can be delivered over a standard internet connection.
Q:
What if my client is working off-line (not connected to internet or corporate network)? Will the policy still function?
A: Yes. As long as the policy was delivered, the Viewfinity Agent will make sure that the policy is always functioning, even on a disconnected PC.
Q:
I am managing multiple remote small offices. My clients do not have Active Directory. Can I still use your product
in order to deliver policies and distribute software?
A: Yes, Viewfinity supports all product functions for both Active Directory and workgroup clients.
Q:
How can I be sure that Privilege Management and other policies such as Block have been delivered and executed
properly on a large group of users/computers?
A: Viewfinity provides detailed reporting on all administrator privilege policies, including an audit trail report that provides confirmation that a policy has been delivered and activated on endpoint devices. This includes validation of policy delivery to mobile and remote users, single or group of computers and/or for a specific application.
Q:
Can I audit specific desktops for suspicious activity? For example, internal data copy, deletion, etc.?
A: Yes. Viewfinity's Activity Recording feature records on a desktop level all activity generated by users including file copy, move, and delete events, using external devices such as USB, installation of software, etc.
Q:
My company's polices don't permit use of Instant Messenger inside the corporate network. However,
I would like to allow the use of Skype for some users. It is difficult for the IT team to maintain such a setup.
Can Viewfinity help me?
A: Yes. Viewfinity allows for very flexible application policies. For example, a block policy can be created to block usage of certain software only when a computer is authenticated against the internal Active Directory or network. At the point when a computer is disconnected, applications can be automatically unblocked without any manual steps from the IT team.
Q:
I would like to allow my clients to use only approved applications and want to make sure that no non-approved applications are used.
Can Viewfinity help me?
A: Yes. Viewfinity supports a "white list" mode in which the Administrator can create a policy and list approved applications. All other applications will be automatically blocked.