Lock and Unlock policies
Know the different lock and unlock policies, where to find and set these policies, their descriptions, and their default values.

pid_script_lock_enabled| IMS Entry | Enable lock script during locking of the user's AccessAgent session? |
| Location | |
| Description | Whether to enable running the lock script when
locking the AccessAgent session
of the user. Note:
Important:
When
using Microsoft Windows 7 or later:
Blocking lock scripts are not supported. The scripts are expected to perform non-blocking actions. For instance, a message box prompt in the script is not supported. |
| Registry | |
| Type | Boolean |
| Values |
|
| Scope | User |
| Note | Refreshed on sync. |
pid_script_lock_type| IMS Entry | Lock script type |
| Location | |
| Description | Type of lock script to run. Note:
|
| Registry | |
| Type | Positive integer |
| Values |
|
| Scope | User |
| Note | Refreshed on sync. |
pid_script_lock_code| IMS Entry | Lock script code |
| Location | |
| Description | Source code of lock script to run. Note:
|
| Registry | |
| Type | String |
| Values | |
| Scope | User |
| Note | Refreshed on sync. |
pid_script_unlock_enabled| IMS Entry | Enable unlock script when user unlocks an existing AccessAgent session? |
| Location | |
| Description | Whether to enable the running of the unlock
script when the user unlocks an existing AccessAgent session. Note:
|
| Registry | |
| Type | Boolean |
| Values |
|
| Scope | User |
| Note | Refreshed on sync. |
pid_script_unlock_type| IMS Entry | Unlock script type |
| Location | |
| Description | Type of unlock script to run. Note:
|
| Registry | |
| Type | Positive integer |
| Values |
|
| Scope | User |
| Note | Refreshed on sync. |
pid_script_unlock_code| IMS Entry | Unlock script code |
| Location | |
| Description | Source code of unlock script to run. Note:
|
| Registry | |
| Type | String |
| Values | |
| Scope | User |
| Note | Refreshed on sync. |
✓
pid_unlock_option

pid_unlock_option| IMS Entry | Unlock computer policy |
| Location | |
| Description | Unlock computer policy for controlling who can
unlock a computer when it is locked by a user who is logged on to AccessAgent.
Same user refers to the same user who locked the computer. Administrator
refers to the Windows user
with Administrator privilege on that computer. The Wallet must contain
the Windows credentials of
an Administrator user on that computer. Note:
Important: Limitations for Microsoft Windows 7
or later versions:
|
| Registry | [DO] "UnlockOption" |
| Type | DWORD Positive integer |
| Values |
|
| Scope | Machine User |
| Note |
|

pid_unlock_different_user_action_countdown_secs| IMS Entry | Confirmation countdown duration, in seconds, for unlocking by a different user |
| Location | |
| Description | Confirmation countdown duration, in seconds,
for unlocking by a different user. Set the value to 0 to disable confirmation
countdown Note:
|
| Registry | [DO] "UnlockDifferentUserActionCountdownSecs" |
| Type | DWORD Non-negative integer |
| Values | 0: to not enable confirmation countdown |
| Scope | Machine User |
| Note |
|
pid_lock_option| IMS Entry | Screen lock option |
| Location | |
| Description | Type of screen lock to be used when the computer
is locked. Note:
|
| Registry | [DO] "LockOption" |
| Type | DWORD |
| Values |
|
| Scope | Machine |
| Note | Refreshed on use. |
pid_lock_transparent_text| IMS Entry | Transparent screen lock message |
| Location | |
| Description | Configurable text for transparent screen lock. Note: Effective
only if pid_lock_option is 2.
|
| Registry | [DO] "LockTransparentText" |
| Type | SZ |
| Values | Tap your RFID card or Ctrl-Alt-E to unlock. (default value) |
| Scope | Machine |
| Note | The text box can contain up to 40 characters. Refreshed on use. |
pid_lock_transparent_hot_key_enabled| IMS Entry | Enable transparent screen lock hot key? |
| Location | |
| Description | Whether the Ctrl-Esc Hot Key sequence is enabled
during transparent screen lock. Note:
|
| Registry | [DO] "LockTransparentHotKeyEnabled" |
| Type | DWORD |
| Values |
|
| Scope | Machine |
| Note | Refreshed on use. |
pid_unlock_with_win_option| IMS Entry | Option for allowing unlock bypass through Windows |
| Location | |
| Description | Option for unlocking the computer with Windows unlock. Note:
|
| Registry | [DO] "UnlockWithWinOption" |
| Type | DWORD |
| Values |
|
| Scope | Machine |
| Note | Refreshed on use. |
pid_unlock_user_name_prefill_option| IMS Entry | User name prefill option for unlock prompt |
| Location | |
| Description | Option for pre-filling the AccessAgent unlock
prompt with a user name.
|
| Registry | [DO] "UnlockUserNamePrefillOption" |
| Type | DWORD |
| Values |
|
| Scope | Machine |
| Note | Refreshed on use. |
pid_fast_unlock_enabled| IMS Entry | Enable fast unlock without IMS Server check? |
| Location | |
| Description | Whether to allow AccessAgent to unlock a computer using a second authentication factor, without any checks with the IMS Server. |
| Registry | |
| Type | Boolean |
| Values |
|
| Scope | Machine |
| Note |