Most of the world still runs on Active Directory. Most of it is not properly secured.
IS Decisions makes Active Directory security practical. Their two products, UserLock and FileAudit, give IT teams the MFA, access controls, session monitoring, and file audit trails they need — without ripping out existing infrastructure or adding operational complexity.
IS Decisions is built specifically for organisations that run Windows and Active Directory environments. If your organisation is Microsoft-centric and you need to add MFA, access controls, and audit capabilities without replacing your identity infrastructure, this is where IS Decisions fits.

Active Directory secures the network. But Active Directory alone is not enough.
Windows Active Directory has been the backbone of enterprise identity management for decades. Most organisations in the region rely on it. The problem is that AD was not built for the threat landscape that exists today. Compromised credentials, password sharing, and a lack of visibility into who is doing what are exactly the kinds of gaps that attackers exploit.

Credentials get compromised. AD does not stop them.
When a username and password are stolen, Active Directory lets the attacker straight in. Without MFA and contextual access controls layered on top, compromised credentials mean compromised access.

No visibility into what users are actually doing.
Native Windows event logs are difficult to work with and rarely provide the session-level clarity IT teams need. Without centralised monitoring, suspicious activity goes undetected and audit preparation becomes a manual ordeal.

File access is an audit blind spot.
Regulators want to know who accessed which files, when, and what they did with them. Without dedicated file auditing, organisations cannot answer that question reliably — and the first time they try is often during an incident or an audit.

Two products. One clear purpose: securing the access layer your organisation already depends on.
IS Decisions keeps its product range focused. UserLock secures Active Directory logons and sessions. FileAudit monitors what happens to files once users are inside. Together they close the two most common access security blind spots in Windows environments.
UserLock
MFA, contextual access policies, SSO, and real-time session management for Active Directory — on-premises and hybrid.
Workforce identity
Secure access for employees, contractors, and administrators across all internal applications and services

What makes UserLock different from standard Active Directory security tools.
.avif)
Contextual access policies
Go beyond username and password. Restrict access by workstation, device, IP range, time of day, session type, and geographic location. If a login attempt does not match the expected context for that user, it is blocked automatically — even if the credentials are valid.
Session management and monitoring
See every active session across your network in real time. Administrators can join, monitor, pause, or terminate sessions without waiting for a report. Concurrent login limits prevent shared credentials from creating unattributed access.
MFA without replacing Active Directory
UserLock adds MFA at the Windows authentication layer using a custom credential provider. This means MFA works across all logon types — workstation, remote desktop, VPN, SaaS — without requiring a new identity provider or replacing existing AD infrastructure.
Certificate-based authentication
UserLock 13.0 adds certificate-based authentication for environments that require it. This works in conjunction with MFA and contextual access policies to provide the highest levels of identity assurance available in a Windows environment.
Compliance-ready reporting
Generate searchable, exportable reports across logons, session history, MFA events, file access, and administrator actions. Reports are designed to answer the specific questions that regulators and auditors ask, without requiring manual log analysis.
Hybrid coverage
UserLock extends AD identity security into hybrid environments, covering cloud applications alongside on-premises resources. SaaS applications are protected through SSO with MFA enforced at the point of access.
Built for the compliance requirements that matter in regulated sectors.
IS Decisions has mapped UserLock and FileAudit capabilities to the most common compliance frameworks. For organisations subject to regulatory audit, the combination of access controls, session monitoring, and file audit trails provides the evidence that auditors require.

IS Decisions is purpose-built for AD-first environments in regulated industries.
Financial services
Banks and financial institutions running Windows environments need to demonstrate strong access controls and complete audit trails to satisfy regulators. UserLock provides the MFA, session controls, and reporting that NCA, SAMA, and NESA frameworks require — without replacing the AD infrastructure already in place.
Government and public sector
Public sector organisations with Windows-heavy environments need access security that works within existing infrastructure constraints. IS Decisions deploys on-premises with no cloud dependency, making it suitable for environments with strict data sovereignty requirements.
Healthcare
Healthcare organisations must control access to patient data and produce evidence of that control for compliance purposes. FileAudit provides the file-level audit trail that healthcare regulators require, while UserLock enforces access policies at the point of login.
Any organisation using Windows and Active Directory
If your organisation runs on Windows and relies on Active Directory, UserLock and FileAudit address the specific security gaps that AD leaves open. No infrastructure replacement needed. Works with what you already have.
Trusted by IT teams who need security that actually works day to day.
"UserLock is a great software that allows us to verify each user's identity, stop password sharing, and help avoid security breaches."

"UserLock offers a level of protection that small, medium, and large businesses should be implementing as part of their security roadmap."

"The setup was very straightforward — it just works right out of the box. Reports and alerts show auditors that we can control access to the most sensitive folders."

"In a flash, I can control my users' login experience, find users' computers, and remote in for support. I cannot imagine working without it now."



How a typical engagement looks
Assessment
Policy design
Deploy
Configure
Train
Support

Compliance

Frequently Asked Questions
IS Decisions provides access security for Windows Active Directory and cloud environments, adding MFA, access control and auditing to AD infrastructure. Its products let organisations attribute every session to a single identified user rather than a shared account.
UserLock is IS Decisions' access security product for Windows Active Directory, adding multi-factor authentication, session management and contextual access restrictions. It works with existing AD rather than replacing it, which is why it is commonly used to secure environments that cannot be migrated.
IS Decisions applies concurrent session limits and single-point-of-entry rules so one account cannot be used from several machines at once, plus context-aware restrictions by workstation, organisational unit, IP address and time. Shared credentials stop working in practice, not just in policy.
FileAudit is IS Decisions' file access auditing product, tracking who accessed which files and when across Windows file servers. Access control determines who could reach data; file auditing evidences who actually did, which is what most regulatory frameworks require.
Yes. IS Decisions covers Windows Active Directory and cloud environments, which reflects how most organisations actually operate — a hybrid estate where on-premises AD still governs core access while applications have moved to cloud services.
The Kernel distributes IS Decisions across the UAE, Middle East, Africa and CIS through its channel partner network, with regional support for deployment into existing Active Directory environments and policy configuration.
Ready to close the gaps that Active Directory leaves open?
Talk to our team. We will assess your current AD environment and show you exactly where UserLock and FileAudit strengthen your security posture.

