IS Decisions

Most of the world still runs on Active Directory. Most of it is not properly secured.

IS Decisions makes Active Directory security practical. Their two products, UserLock and FileAudit, give IT teams the MFA, access controls, session monitoring, and file audit trails they need — without ripping out existing infrastructure or adding operational complexity.

25+
Years of Active Directory security expertise
3400+
Organisations across every sector
120+
Countries where UserLock is deployed
2
Products. One clear focus: AD security

IS Decisions is built specifically for organisations that run Windows and Active Directory environments. If your organisation is Microsoft-centric and you need to add MFA, access controls, and audit capabilities without replacing your identity infrastructure, this is where IS Decisions fits.

The problem

Active Directory secures the network. But Active Directory alone is not enough.

Windows Active Directory has been the backbone of enterprise identity management for decades. Most organisations in the region rely on it. The problem is that AD was not built for the threat landscape that exists today. Compromised credentials, password sharing, and a lack of visibility into who is doing what are exactly the kinds of gaps that attackers exploit.

Two-factor authentication push app screenshot
01

Credentials get compromised. AD does not stop them.

When a username and password are stolen, Active Directory lets the attacker straight in. Without MFA and contextual access controls layered on top, compromised credentials mean compromised access.

02

No visibility into what users are actually doing.

Native Windows event logs are difficult to work with and rarely provide the session-level clarity IT teams need. Without centralised monitoring, suspicious activity goes undetected and audit preparation becomes a manual ordeal.

03

File access is an audit blind spot.

Regulators want to know who accessed which files, when, and what they did with them. Without dedicated file auditing, organisations cannot answer that question reliably — and the first time they try is often during an incident or an audit.

Products

Two products. One clear purpose: securing the access layer your organisation already depends on.

IS Decisions keeps its product range focused. UserLock secures Active Directory logons and sessions. FileAudit monitors what happens to files once users are inside. Together they close the two most common access security blind spots in Windows environments.

UserLock

MFA, contextual access policies, SSO, and real-time session management for Active Directory — on-premises and hybrid.

MFA at the Windows authentication layer, without replacing AD
Contextual access policies by IP, time, device, location, and session type
Single sign-on to on-premises and SaaS applications
Real-time session monitoring with admin intervention capability
Concurrent login prevention and session limits
Certificate-based authentication (UserLock 13.0)
Full audit reports for compliance and cyber insurance
Deployable with no extra infrastructure required

Workforce identity

Secure access for employees, contractors, and administrators across all internal applications and services

Real-time visibility into who accessed which files and when
Alerts on suspicious access, modification, or deletion events
NTFS permissions reporting across file servers
Audit trail searchable by user, group, or organisational unit
Coverage across Windows file servers and cloud storage
Exportable reports for compliance evidence
Automated responses to defined access events
Works alongside UserLock in the same console
Key capabilities

What makes UserLock different from standard Active Directory security tools.

Software download screenshot

Contextual access policies

Go beyond username and password. Restrict access by workstation, device, IP range, time of day, session type, and geographic location. If a login attempt does not match the expected context for that user, it is blocked automatically — even if the credentials are valid.

Session management and monitoring

See every active session across your network in real time. Administrators can join, monitor, pause, or terminate sessions without waiting for a report. Concurrent login limits prevent shared credentials from creating unattributed access.

MFA without replacing Active Directory

UserLock adds MFA at the Windows authentication layer using a custom credential provider. This means MFA works across all logon types — workstation, remote desktop, VPN, SaaS — without requiring a new identity provider or replacing existing AD infrastructure.

Certificate-based authentication

UserLock 13.0 adds certificate-based authentication for environments that require it. This works in conjunction with MFA and contextual access policies to provide the highest levels of identity assurance available in a Windows environment.

Compliance-ready reporting

Generate searchable, exportable reports across logons, session history, MFA events, file access, and administrator actions. Reports are designed to answer the specific questions that regulators and auditors ask, without requiring manual log analysis.

Hybrid coverage

UserLock extends AD identity security into hybrid environments, covering cloud applications alongside on-premises resources. SaaS applications are protected through SSO with MFA enforced at the point of access.

Compliance

Built for the compliance requirements that matter in regulated sectors.

IS Decisions has mapped UserLock and FileAudit capabilities to the most common compliance frameworks. For organisations subject to regulatory audit, the combination of access controls, session monitoring, and file audit trails provides the evidence that auditors require.

NCA (Saudi Arabia)
NESA (UAE)
SAMA
ISO 27001
GDPR
HIPAA
PCI-DSS
SOC 2
NIST
Who this is for

IS Decisions is purpose-built for AD-first environments in regulated industries.

Mobile banking icon

Financial services

Banks and financial institutions running Windows environments need to demonstrate strong access controls and complete audit trails to satisfy regulators. UserLock provides the MFA, session controls, and reporting that NCA, SAMA, and NESA frameworks require — without replacing the AD infrastructure already in place.

Public administration icon

Government and public sector

Public sector organisations with Windows-heavy environments need access security that works within existing infrastructure constraints. IS Decisions deploys on-premises with no cloud dependency, making it suitable for environments with strict data sovereignty requirements.

Healthcare icon

Healthcare

Healthcare organisations must control access to patient data and produce evidence of that control for compliance purposes. FileAudit provides the file-level audit trail that healthcare regulators require, while UserLock enforces access policies at the point of login.

Software icon

Any organisation using Windows and Active Directory

If your organisation runs on Windows and relies on Active Directory, UserLock and FileAudit address the specific security gaps that AD leaves open. No infrastructure replacement needed. Works with what you already have.

What customers say

Trusted by IT teams who need security that actually works day to day.

"UserLock is a great software that allows us to verify each user's identity, stop password sharing, and help avoid security breaches."

José Miguel Villafuerte
IT Infrastructure Manager, Teleperformance

"UserLock offers a level of protection that small, medium, and large businesses should be implementing as part of their security roadmap."

Ricky Magalhaes
Information Security Analyst

"The setup was very straightforward — it just works right out of the box. Reports and alerts show auditors that we can control access to the most sensitive folders."

Paul Rickerby
IT Manager, Cleaver Fulton Rankin

"In a flash, I can control my users' login experience, find users' computers, and remote in for support. I cannot imagine working without it now."

Bob Burchett
Server Administrator, St. Clair County Board of Education
Vendor product screenshot
The Kernel symbol
How the Kernel Helps

IS Decisions is straightforward to deploy. We make sure it is deployed correctly for your environment from day one.

The Kernel is IS Decisions' authorised distribution partner across the UAE and the wider MEA region. UserLock and FileAudit are designed to install quickly and work without significant configuration overhead. Our role is to make sure they are scoped correctly for your environment, configured to match your access policies, and mapped to the compliance requirements your organisation needs to demonstrate.

We work with organisations across financial services, government, and healthcare across the region and we understand the specific access control requirements that regulators in the UAE, Saudi Arabia, and South Africa expect to see.

120+

Countries where IS Decisions software is trusted by over 3,400 organisations in finance, government, healthcare, and critical infrastructure

01

Environment assessment

We start by understanding your Active Directory environment, your existing access policies, and the compliance requirements you need to meet. From this we define the right configuration for UserLock and FileAudit before any deployment begins.

02

Deployment and configuration

UserLock and FileAudit deploy without additional infrastructure, but they need to be configured correctly for your AD structure, your user groups, and your security policies. We handle this to ensure access controls are enforced correctly from the start.

03

Access policy design

Contextual access policies are where UserLock delivers its most distinctive value. We work with your IT team to design policies that reflect how your users actually work — by location, device, time, and session type — without creating friction for legitimate access.

04

Compliance mapping

We map UserLock and FileAudit's reporting capabilities to the specific compliance frameworks your organisation is subject to, so that when auditors ask for access evidence, you can produce it quickly and completely.

05

IT team enablement

We train your IT administrators on day-to-day use of both products, including how to respond to alerts, interpret session reports, and update access policies as your environment evolves.

06

Ongoing regional support

We provide regional support after deployment for policy updates, new user onboarding, and any changes to your compliance requirements. A team based in the region that understands your environment.

How a typical engagement looks

01

Assessment

AD environment and compliance scope
02

Policy design

Access rules per user group and context
03

Deploy

UserLock and FileAudit installation
04

Configure

MFA, contextual rules, and alerts
05

Train

IT team enablement on daily operations
06

Support

Ongoing regional contact

Compliance

NCA (Saudi Arabia)
NESA (UAE)
SAMA
ISO 27001
GDPR
PCI-DSS
HIPAA
SOC 2

Frequently Asked Questions

IS Decisions provides access security for Windows Active Directory and cloud environments, adding MFA, access control and auditing to AD infrastructure. Its products let organisations attribute every session to a single identified user rather than a shared account.

UserLock is IS Decisions' access security product for Windows Active Directory, adding multi-factor authentication, session management and contextual access restrictions. It works with existing AD rather than replacing it, which is why it is commonly used to secure environments that cannot be migrated.

IS Decisions applies concurrent session limits and single-point-of-entry rules so one account cannot be used from several machines at once, plus context-aware restrictions by workstation, organisational unit, IP address and time. Shared credentials stop working in practice, not just in policy.

FileAudit is IS Decisions' file access auditing product, tracking who accessed which files and when across Windows file servers. Access control determines who could reach data; file auditing evidences who actually did, which is what most regulatory frameworks require.

Yes. IS Decisions covers Windows Active Directory and cloud environments, which reflects how most organisations actually operate — a hybrid estate where on-premises AD still governs core access while applications have moved to cloud services.

The Kernel distributes IS Decisions across the UAE, Middle East, Africa and CIS through its channel partner network, with regional support for deployment into existing Active Directory environments and policy configuration.

Ready to close the gaps that Active Directory leaves open?

Talk to our team. We will assess your current AD environment and show you exactly where UserLock and FileAudit strengthen your security posture.