Policy Actions
Overview
Once a user is successfully authenticated and has met the conditions outlined in the conditions profile, the portal admin can configure the actions the user is permitted to carry out when connected to the remote application or server. Beyond specifying the actions that a user can or cannot carry out, the portal admin can also enforce actions carried out by the Cyolo platform.
About Actions
- Actions are created as profiles on the Policies > Actions page of the Cyolo admin portal.
- The Actions page is pre-populated with default action profiles for each application type or protocol. These profiles cannot be deleted but can be edited. When configuring applications, the default profile for the respective application type or protocol is added to the rule. This can be changed to a custom profile.
- Each profile includes actions specific to an application type or protocol.
- An Actions profile can be defined either within an individual application or at the category level.
- Multiple custom Actions profiles can be created, each designed for a specific purpose.
See Actions List - for alphabetical list of all actions
See Actions Available per Protocol and Type - for action availability per app type.
Actions List
- Allow audio input: Enables the use of the local microphone within the remote desktop session. Disabled by default.
- Allow camera: Enables the use of the local camera within the remote desktop session. Disabled by default.
- Allow clipboard: Allows copy, paste, and other clipboard operations when using native clients (RDP, SSH, VNC, TELNET).
- Allow COM redirection: Enables access to the local COM port by applications running in the RDP session. Disabled by default.
- Allow device redirection: Enables access to locally connected devices within the RDP session. Disabled by default.
- Allow drive redirection: Allows users to access files and folders stored on their local drives within the RDP session. Disabled by default.
- Allow port forwarding: Allows secure redirection of network traffic from a local port to a remote port over an SSH connection. Disabled by default.
- Allow printer redirection: Enables access to local printers within the RDP session. Disabled by default.
- Allow secure session collaboration: Allows session owners to generate one-time shareable links for collaboration with internal and external users (up to three links per session).
- Allow smart card redirection: Enables the use of smart cards within the remote session. Disabled by default.
- Allow x11 forwarding: Allows users to run graphical applications on a remote server and display them locally over an SSH connection. Disabled by default.
- Anti-malware scan: Scans files uploaded and downloaded during SMB sessions. Requires anti-malware integration configuration.
- Block URL categories: Blocks access to specified URL categories as part of Secure Web Gateway functionality.
- Disallow file downloads: Prevents users from downloading files from a directory. Disabled by default.
- Disallow file uploads: Prevents users from uploading files to a directory. Disabled by default.
- Enhanced logging: Adds additional logging details for SMB sessions.
- Enforce session fingerprinting: Creates a unique session identifier based on device attributes and restricts access to the original device.
- Log successful user access: Logs successful user login events. Enabled by default.
- Log all IP and port pairs accessed during the session: Logs all network connections, including IP addresses and ports accessed during a session.
- Max session duration (minutes): Limits the maximum duration of a session.
- Native session access token will be valid for (minutes): Defines how long a user has to initiate an RDP or SSH session after launching it. Default is 30 minutes.
- Record session: Enables recording of remote access sessions. Disabled by default.
- SSH command control: Allows administrators to define allowed or denied SSH commands.
- Supervisors can join the application's active sessions: Allows designated supervisors to join active user sessions. Disabled by default.
- Use multiple monitors (not supported in Linux): Enables multi-monitor support for RDP sessions. Disabled by default.
- Web application firewall (WAF): Detects and optionally blocks web application vulnerabilities based on configured rules. See WAF for more details.
Actions Available per Protocol and Type
Web Applications
| Action | HTTP | HTTPS | SaaS | Link |
|---|---|---|---|---|
| Disallow file uploads | ✓ | ✓ | — | — |
| Disallow file downloads | ✓ | ✓ | — | — |
| Enforce session fingerprinting | ✓ | ✓ | ✓ | — |
| Web application firewall (WAF) | ✓ | ✓ | — | — |
| Log successful user access | ✓ | ✓ | ✓ | ✓ |
| Log all IP and port pairs accessed during the session | ✓ | ✓ | — | — |
Networks
| Action | SSH Tunnel | DesktopApp | Network | TCP |
|---|---|---|---|---|
| Native session access token will be valid for (minutes) | ✓ | — | — | — |
| Enforce session fingerprinting | ✓ | — | — | — |
| Log successful user access | ✓ | ✓ | ✓ | ✓ |
| Log all IP and port pairs accessed during the session | — | — | ✓ | — |
Servers
| Action | SSH | RDP | VNC | TELNET |
|---|---|---|---|---|
| Allow clipboard | ✓ | ✓ | ✓ | ✓ |
| Record session | ✓ | ✓ | ✓ | ✓ |
| Supervisors can join the application's active sessions (see limitation below) | ✓ | ✓ | ✓ | ✓ |
| Allow port forwarding | ✓ | — | — | — |
| Allow x11 forwarding | ✓ | — | — | — |
| Native session access token will be valid for (minutes) | ✓ | ✓ | ✓ | ✓ |
| Max session duration (minutes) | ✓ | ✓ | ✓ | ✓ |
| Allow drive redirection | — | ✓ | — | — |
| Allow device redirection | — | ✓ | — | — |
| Allow printer redirection | — | ✓ | — | — |
| Use multiple monitors (not supported in Linux) | — | ✓ | — | — |
| Allow camera | — | ✓ | — | — |
| Allow audio input | — | ✓ | — | — |
| Allow COM redirection | — | ✓ | — | — |
| Allow smart card redirection | — | ✓ | — | — |
| SSH command control | ✓ | — | — | — |
| Enforce session fingerprinting | ✓ | ✓ | ✓ | ✓ |
| Log successful user access | ✓ | ✓ | ✓ | ✓ |
| Allow secure session collaboration | ✓ | ✓ | ✓ | — |
Databases
| Action | MySQL | PSQL |
|---|---|---|
| Max session duration (minutes) | ✓ | ✓ |
| Log successful user access | ✓ | ✓ |
Files
| Action | SMB |
|---|---|
| Disallow file uploads | ✓ |
| Disallow file downloads | ✓ |
| Enhanced logging | ✓ |
| Enforce session fingerprinting | ✓ |
| Log successful user access | ✓ |
| Anti malware scan | ✓ |
RDP Action Policies
| Web RDP | Native RDP | |
|---|---|---|
| Allow clipboard | + | + |
| Record session | + | + |
| Supervisors can join the application's active sessions | + | _ |
| Native session access token will be valid for (minutes) | _ | + |
| Max session duration (minutes) | + | + |
| Allow drive redirection | _ | + |
| Allow device redirection | _ | + |
| Allow printer redirection | _ | + |
| Use multiple monitors (not supported in Linux) | _ | + |
| Allow camera | _ | + |
| Allow audio input | _ | + |
| Allow smart card redirection | _ | + |
Note- RDP Known Limitations
In Web sessions, Cyolo can limit access to specific native apps. However, in native mode it cannot.
System Limitation - Automatic Session Timeout
When supervisor participation is enabled, session duration depends on whether approval is required:
-
No approval required — the session will automatically terminate after 60 minutes, regardless of activity.
-
Approval required — the approved access mode governs the session duration:
- Immediate Access — the session begins once approved and remains active until the user logs out or one hour elapses, whichever occurs first.
- Scheduled Access — the session can be initiated only within the approved start and end timeframe. Once initiated within that window, access remains active until the end time, at which point the session expires. The user cannot initiate a new session after the timeframe ends.
- Timed Access — the session begins upon approval and remains active across logouts for the full approved duration.
When supervisor participation is disabled and no approval is required, the session remains active until the user logs out.
Updated 2 months ago