LogoLogo
DownloadGet a QuoteConnect with Us
  • Introduction
    • What is Thinfinity® Workspace
    • About this Document
  • Product Overview
    • Architecture Components
    • Load Balancing
    • Deployment Scenarios Overview
    • Connectivity
      • Remote Desktop Access
      • Remote Application Access
      • Terminal Access
    • RPAM and Resource Reservation
    • Cloud Manager
    • Audit Logging
    • User Analytics
  • Getting Started
    • Basic Installation
    • Accessing Thinfinity® Workspace in Your Browser
    • Connection Types
      • Remote Desktop Connection
      • Remote App Connection
      • Remote Intranet Web App Connection
      • Telnet SSH Connection
    • Configuration
    • Security
    • Beyond the Basics
  • Reference
    • Thinfinity® Workspace Configuration Manager
      • General Tab
      • Broker Tab
      • Authentication Tab
        • Methods Tab
          • API Access Settings
          • RADIUS Settings
          • SAML Settings
          • OAuth 2.0 Settings
          • External DLL
        • Mappings Tab
        • 2FA Tab
        • Directory Services Tab
          • Local Computer Users Settings
          • Local Computer Users
          • Local Thinfinity IdP Settings
          • Computer Domain Settings
          • External Domain Settings
      • Access Profiles Tab
        • The [+] Access Profile
        • Desktop Access Profiles
          • RDC Access Profile
            • Core Settings
            • User Experience Settings
          • ThinVNC Access Profile
          • VNC/RFB Access Profile
            • User Experience Settings
        • Application Access Profiles
          • Remote App Access Profile
            • Core Settings
          • Web App Access Profiles
            • Web Link Access Profile
            • WAG Access Profile
          • VirtualUI App Access Profile
            • Core Settings
        • Web Folder Access Profile
        • Terminal Access Profiles
          • z/Scope Classic Access Profile
          • Telnet/SSH Access Profile
            • Core Settings
            • User Experience Settings
        • Label
        • Access Control Settings
      • VirtualUI Tab
      • Folders Tab
      • Permissions Tab
      • Protection Tab
      • Notifications Tab
      • Database Tab
      • z/Scope Classic Tab
      • Services Tab
      • License Tab
    • Thinfinity® Workspace Web Manager
      • Access Profiles
        • Desktop Access Profiles
          • RDC Access Profile
            • Core Settings
            • User Experience Settings
          • VNC
            • Core Settings
            • User Experience Settings
          • Thinfinity VNC
            • Core Settings
        • Application Access Profiles
          • Remote App
          • Web App
            • Web Application Gateway (WAG)
            • Web Link
          • VirtualUI App
        • Web Folder Access Profile
          • Core Settings
        • Terminal Access Profiles
          • Telnet SSH Terminal
          • Multi Terminal
        • Access Control Settings - Web Manager
      • Addons
        • Analytics
        • Brokers Monitor
        • Audit Log
        • Recordings
        • Members
        • Reports
        • Resource Reservation
    • Thinfinity® Gateway
  • Configuration
    • RBAC and Resource Reservation
      • Configuring the Resource Reservation Feature
      • Role Definition with Permissions Groups
      • Granting Approver or Requester Role to a User
      • Enabling Resource Reservation
      • Granting a User Access to a Single Access Profile
      • Granting Access Permissions for a Group of Access Profiles
      • Grouping Access Profiles Under a Label
      • Restricting Access to a Resource
      • Exception Days - No Booking Allowed
      • Booking a Resource
      • Approving a Booking Request
    • Security
      • Managing the SSL Certificate
        • Creating a Self-Signed Certificate
        • Creating a CA Certificate Request
        • Importing a Certificate
        • Using ACME Certificates
      • Session Recording
        • Viewing Recorded Sessions
    • User Experience
      • Bidirectional Audio Redirection
      • Customizing the Thinfinity® Workspace Toolbar
        • Using web.settings.js
        • Using the SDK 'connect' Method
        • Extend the Thinfinity® Workspace Toolbar
      • Customize Translation
      • GFX and H.264 Support
        • Enabling H.264 for an Access Profile
        • Preparing a Remote Desktop for H.264 Support
      • How to Enable Multi-Monitor
      • Multi-Touch Redirection
      • Redirecting Devices
      • Remote FX
      • Enhanced Browser and DPI Support
        • Display Model Inheritance
        • Properties Reference Tables
        • The Calculation Process
        • Example
    • Extended Features
      • Remote Active Directory
        • How to Install and Configure Thinfinity® Remote AD Services
        • Active Directory Credentials Mapping
      • WebBridge - Direct File Transfer
        • Installing Thinfinity® WebBridge
        • Using WebBridge
      • Silent Install Options
    • License Server Manager
      • Proxy Activation
      • Get a New Trial Serial Number
      • Activate a Serial Number Online
      • Activate a Serial Number Offline
      • Registering a License with License Server Manager
  • Deployment Scenarios
    • Single Machine Deployment
    • Distributed Deployment
    • Multitenant - Several Subdomains
    • Implementing Secondary Brokers Scenarios
      • Resource Pools
      • OT Networks
      • Multitenant - Single Domain
  • Integrations
    • Integrating Thinfinity® Workspace
    • External Authentication
      • API Key
    • Customizing the Web Interface
      • Customizing the Logo
      • Organizing custom files
    • One-Time-URL (OTURL)
      • Customizing OTURL Connection
      • Enabling Features
  • Mobile Devices
    • Mobile Devices
    • Accessing Thinfinity® Workspace
    • Mouse Control
    • Keyboards and Toolbars
    • Gestures
Powered by GitBook
On this page

Was this helpful?

  1. Reference
  2. Thinfinity® Workspace Configuration Manager
  3. Access Profiles Tab

Access Control Settings

PreviousLabelNextVirtualUI Tab

Last updated 2 months ago

Was this helpful?

Access Control Settings are available for every access profile in the Permissions, Restrictions, Access Hours and Authentication tabs of the access profile editor window. Find below details on each of the available options.

The options available in the Permissions tab allow the admin to determine which users or groups can access a specific resource (access profile).

In the Profile Editor select the Permissions tab.

Option
Description

Inherit label access permissions

Allow anonymous access

This option is selected by default and makes the access profile available without any type of authentication, that is, anyone accessing Thinfinity Workspace will be able to access the profile.

Group or user names

Add button allows choosing the local domain users and groups who can access the profile. Displays the Windows Select Users or Groups allowing the selection of Active Directory users. Add button only becomes available if Allow anonymous access option is de-selected.

Only users who authenticate with their correct Windows username and password will be able to use this access profile. (*) Remove button allows deleting a user or group from the list of users or groups allowed to access the profile.

Permission Groups

Offers access to the permissions groups editor. See the paragraphs below for details.

Reservation buffer

Allows the admin to set the buffer size in which concurrent reservations are allowed. Used in conjunction with the Reservation limit parameter.

Reservation limit

Allows setting the number of concurrent reservations for the resource (the number of simultaneous users).

(*) Thinfinity Workspace supports a user changing the password at their next logon within the web interface. Make sure to uncheck the Use standard browser authentication dialog to enable this option.

If you want a user or a user group to access more than one resource, you need to create more access profiles and then add this user to each access profile. The authenticated user will be able to choose which one of the available access profiles to connect to. Clicking the Permission Groups button will display the following dialog window:

The following options are available:

Option
Description

Drop-down field

Lists the permissions groups (roles) defined in the system.

[+] button

Adds a new permissions group (role) to the list.

R button

Allows renaming the selected permissions group or role.

[-] button

Removes the selected permissions group or role.

Here is a description of each type of permission:

Permission
Description

Access

Enables immediate access to the profile.

Requires approval

Indicates that the user request requires an approval.

Approve access

Can authorize / approve reservation request.

Self reserve

Can create reservations for oneself.

Others can reserve

Can be added by others for the use of a resource.

Reserve for others

Can create reservations for others.

Allow Recurrency

Can create recurring reservations.

The options available in the Restrictions tab allow the admin to define a whitelist and a blacklist of IP addresses allowed to connect the access profile.

In the Profile Editor of your access profile select the Restrictions tab.

Option
Description

No restrictions

No restriction as to which IP Addresses will be able to connect to the access profile.

Allow only from these IPs

Allow connections from the listed IP Addresses.

Block connections from these IPs

Block connections from the listed IP Addresses.

Add

Click to add an IP Address to the list.

Remove

Select an IP from the list then click this button to remove it.

In the Access Hours tab of a access profile Editor, you can define the specific days and times during which the resource will be available to users, allowing you to set a time range for its usage.

In the Profile Editor of your access profile select the Restrictions tab.

Option
Description

Access Allowed

Define the days and the hours when the resource (desktop, app, folder, terminal) will be available.

Access Denied

Define the days and the hours when the resource (desktop, app, folder, terminal) will be disabled.

Allow Access only within this period

Define a specific time interval during which the resource (desktop, app, folder, terminal) will be available.

Note that this tab will only become available if Allow Anonymous Access option from the Permissions tab is deselected.

The Authentication Methods tab allows you to customize the authentication methods for the selected access profile.

Option
Description

No restrictions

No restriction on the authentication method used.

Only users authenticated with these methods

Only the users authenticated with the selected methods will be able to see and connect to the resource (desktop, app, folder, terminal).

This option is selected by default and makes the current access profile available to all the users or groups who can access the Label selected for this access profile. For details, see .

For details on how to manage permissions and roles, see and .

Resource Reservation
Role Definition - Permissions Groups
Label