ProductShieldMSPPricingCompareBlogDocsStart for FreeSign InTR
Windows Login MFA

A per-person second step for Windows sign-ins.
Without touching your password.

Dynacop adds a person-owned verification step to console and RDP sign-ins. Windows verifies the password; Dynacop never sees or stores it. You decide which sign-ins require MFA, how long it waits, and what happens when the internet is down.

The order at sign-in
Windows verifies the password
The person enters their own code
Policy decides
The session opens
✓ Windows 10/11 · Server 2012+✓ RDP and console✓ No Active Directory required✓ Deploy via MSI / GPO / RMM✓ Signed installer

Your sign-in experience doesn't change; one step is added.

Dynacop is a credential provider that wraps Windows' own sign-in flow — it doesn't replace the flow, it adds person verification on top.

Your password never touches Dynacop

Windows verifies the password as always; Dynacop never sees, transmits, or stores it. Our job starts after the password: verifying that the person entering the code really is that person.

Console and RDP alike

The same flow runs whether someone is at the machine or connecting over Remote Desktop. The outcome is recorded under the person's name, along with the session type.

Existing flow and autologon preserved

Thanks to the wrapping architecture, your current sign-in experience — including automatic logon — is inherited as-is. Remove the agent and the Windows sign-in returns to exactly what it was.

Dynacop — Verification
Enter the 6-digit code from your phone
4 8 1 0 5 2
Time remaining: 47 s

If time runs out, the RDP session is safely disconnected; on console, you return to the sign-in screen.

What happens when the internet is down?

It's the first question of every MFA evaluation — and it deserves an honest answer. The decision is yours; the default is to lock nobody out.

When the cloud is unreachable — the decision table
SituationOutcome
Cloud reachableNormal flow — whatever your policy says
Unreachable · fail-open (default)Password sign-in continues; nobody is locked out
Unreachable · fail-closed + Offline AccessThe code is verified locally, on the machine
Unreachable · fail-closed + no offline enrollmentSign-in is blocked — a deliberate strict choice
The default never turns an outage into a lockout

In fail-open mode, if the cloud is unreachable the MFA screen never appears; users sign in with their password. Access to your server is never held hostage to our availability.

Offline Access: MFA without internet

In strict mode (fail-closed) codes work without internet too: after a successful online verification, the factor is stored encrypted on the machine and verified locally on later sign-ins — the single-use code rule holds offline as well.

Policy makes the call

Fail-open and Offline Access are mutually exclusive: the relaxed mode or the strict mode. The choice lives in your tenant policy and is distributed to the machine encrypted — known even when the cloud is down.

No user limit on offline access.

Offline access is usually capped in this market: Duo's own documentation, for example, limits offline access to 5 users by default, works only with proprietary methods, and requires a higher tier. Dynacop's offline access works for unlimited people, with any TOTP authenticator, and is included in every installation.

You decide where and how MFA is required.

Policy is set per resource; the values below are the real panel defaults.

Policy — SRV-RDP-01
MFA required onRDP only
MFA timeout60 s
Failed-attempt lockout5 attempts / 5 min
Offline AccessOn
New userRequire enrollment
Require by session type

Require MFA on every session, RDP only, or console only. There's also a "monitor only" mode: MFA is never prompted, but auditing, inventory, and attack visibility keep flowing — ideal for a gradual rollout.

The timeout protects the session

If the code isn't entered in time (60 seconds by default), the RDP session is safely disconnected; no door is left waiting open. On console, you return to the sign-in screen.

Lockout on failed attempts

Repeated wrong codes temporarily lock the account (5 attempts / 5 minutes by default), and the lock lifts automatically. The same counter applies to offline sign-ins.

Exemptions are deliberate and visible

You can exempt a person or an account from MFA — but never silently: the exemption is clearly visible in the panel, and sign-ins are still recorded.

Enroll once; verify on every authorized machine.

No proprietary app requirement — any RFC 6238-compliant TOTP app works; the ones below are just examples.

Google AuthenticatorMicrosoft Authenticator1PasswordAuthyFreeOTP
Any TOTP authenticator

Codes are generated with the open TOTP standard (RFC 6238). Your team keeps the app they already use; you never force a new app on anyone.

Enrollment only via a verified invite

The factor is attached through a verified invitation link sent to the person's email — enrollment can't happen at the lock screen. Knowing the password doesn't let anyone attach their own phone.

The factor belongs to the person, set up once

A person enrolls their phone once; they verify with the same factor on every machine and in every workspace they can access. There's no per-machine enrollment, no QR-scanning tour.

How is identity resolved on a shared account? →

Windows MFA — frequently asked questions

Do you see my password?

No. Windows verifies the password as always; Dynacop never sees, transmits, or stores it. What Dynacop verifies is the person, not the password.

Do I get locked out when the internet is down?

Not by default: if the cloud is unreachable, the MFA screen doesn't appear and you sign in with your password. If you choose strict mode (fail-closed), Offline Access takes over: the code is verified locally on the machine. Only the combination of strict mode plus a user with no offline enrollment blocks sign-in — and that's a deliberate choice.

How many users does offline access support?

There's no limit. Every person who completes a successful online verification has their factor stored encrypted on the machine and verified locally during internet-free sign-ins. The "offline for at most N users" cap found in some products doesn't exist in Dynacop.

Which authenticator apps are supported?

Any app that supports the TOTP standard: Google Authenticator, Microsoft Authenticator, 1Password, Authy, and the like. We don't impose a proprietary app; your team keeps what they're used to.

Can I require MFA only for RDP sign-ins?

Yes. Policy is set by session type: every session, RDP only, console only — or "monitor only" mode, where MFA is never prompted but all sign-ins and attack traffic stay visible. It's the most comfortable path for a gradual rollout.

What if I just wait at the code screen?

When the default 60-second window runs out, the RDP session is safely disconnected; on console, you return to the sign-in screen. The window is adjustable from 10 to 600 seconds in policy.

Will my existing sign-in flow or autologon break?

No. Dynacop is a credential provider that wraps Windows' own sign-in flow; the current experience — including automatic logon — is inherited as-is. Remove the agent and the sign-in flow returns to what it was.

What happens to my sign-in if Dynacop itself fails?

When the agent or the cloud is unreachable, your fail-mode policy decides: with the default fail-open, the MFA screen doesn't appear and sign-ins continue with the password — the machine is never stranded. Strict mode (fail-closed) is something you choose deliberately. And if Dynacop is uninstalled, the Windows sign-in flow returns to exactly what it was, with nothing left behind.

Am I locked out if I lose my phone?

No. You have single-use recovery codes; your admin can also reset your factor from the panel, and you re-enroll your new phone through a verified invitation link. Nobody stays permanently locked out.

Which Windows versions does it run on?

Windows 10 and 11, and Windows Server from 2012 onward — 2012 support is field-tested, not assumed. The agent is a lightweight Windows service written in C++.

Do sign-ins get locked if our payment is late?

No, under no circumstances. A billing problem never turns into a security punishment: even if payment is overdue, Windows sign-ins are never locked. You sort out the invoice in the panel; access to your server is not held hostage.

Your first 10 users are free.
Protect your first Windows sign-in in about 4 minutes.

No credit card required · No minimum purchase