Password Sharing Prevention and Per-Seat Licensing
EMS allows only one user per account to access the site. In effect, it grants the user a license to access the online service. Users can share their user name and passwords, but they cannot share a license. Hence there will only be ONE user accessing the site for each paid subscription.
Based on this electronic “license” model, EMS associates a user’s credentials with an electronic certificate that is issued during a successful login. The login procedure can still be handled through a traditional username/password security engine; however, access to the site depends on the existence and validation of the user’s electronic license. The existence of this license certificate does not, however, “lock” the user to that specific computer. Your users are free to access your online service from anywhere with an Internet connection: they simply log in and are automatically issued a new certificate for the computer they are currently using. However, every newly issued certificate, by default, expires the older certificates issued for that account and renders them useless.
Using this mechanism, EMS can discretely track how often your users are moving from one location to the next within a specified period of time. The EMS system administration utility would then allow you to define your acceptable usage policies by creating “Access Rules” and “Action Triggers”. For example it may be acceptable for your subscribers to access your site from 3 different computers within a six-hour period. However, you may want to create an EMS Rule that sets a limit of 4 locations within a two-hour period, and you may assign an Action Trigger to that rule to disable the account if the rule is brocken by a user.
You may define as many EMS Access Rules as you require to completely enforce all your Site Usage Policies. The following standard Action Triggers are available on EMS out-of the box and more can be custom developed for your specific requirements:
- Display warning message to the user but allow access
- Notify system administrator by Email
- Suspend user account for a specified period of time
- Disable user account and request that user contacts you by phone
- Do nothing and simply log the event to gather evidence for litigation or re-negotiation of agreements
Click HERE to try EMS online