Fleetfold Verify

Enterprise MFA for every Windows sign-in

Stop password-only PC access with push approval, anti-phishing codes, and one-toggle USB storage block on enrolled PCs. Built for IT teams that need proof at the lock screen, and control after sign-in, without another SaaS dependency.

Windows logon MFA Verified push USB storage block Kill switch Self-hosted Security Ops

Credentials leak. Logons should not.

Phishing, reused passwords, and stolen sessions still open offices every week. Fleetfold adds a second factor at the Windows Credential Provider so a password alone never completes a desktop session.

Users pick Mobile push or a 6-digit passcode in the Fleetfold Verify dialog. If they deny or report fraud, you can disconnect the workstation that started the challenge.

See how logon works
Fleetfold Verify Windows dialog: choose Mobile push or Passcode

Approve on the phone. Match the code on the PC.

High-priority mobile notifications reach users even when the app is in the background. For high-assurance policies, Fleetfold shows a short 2-digit verification code on the Windows screen. The phone must enter those digits before Approve succeeds.

That blocks blind prompt bombing. A random push from an attacker does not unlock the PC without the code sitting in front of the legitimate user.

Read the security model
Fleetfold verified push: 2-digit code on Windows, entered in the Fleetfold app

What enterprise buyers evaluate

Fleetfold is a complete Windows MFA stack: logon enforcement, mobile approval, policy, audit, and response. Not a dashboard that still leaves the lock screen unprotected.

Push, passcode, offline

Primary phone approve with TOTP fallback and travel or offline packs when networks are unreliable.

Fleetfold MDM

Separate product: selective USB, timed lock, remote wipe, shell lockdown, and browser URL whitelist on enrolled PCs.

Security operations

Anomalies, containment, device posture, playbooks, and evidence packs for real incident response.

Windows Hello coexistence

Allow Hello or FIDO where policy permits, while keeping password logons MFA-first everywhere else.

Infrastructure you control

Run on your host. Enrollment, secrets, and audit stay inside your boundary instead of a mandatory MFA cloud.

Windows-first rollout

Credential Provider, agent, and Android app designed for fleet pilots that need results in days, not quarters.

Lock screen MFA at Windows sign-in, not only for cloud apps
Self-hosted Your server, your policies, your retention
Operator ready Admin console for enrollment, audit, and response

Block USB storage from the same console.

Sign-in MFA stops stolen passwords. USB storage block stops the next step: walking data out on a stick. Toggle Block USB storage in Policies. Enrolled agents apply it automatically, eject mounted sticks, and keep deny sticky across reboot.

One agent. One policy. MFA at the lock screen plus removable-media control after logon, without buying a separate USB DLP tool for the fleet.

See USB storage control
Fleetfold Verify blocking USB storage on a Windows 11 PC

Protect the fleet, not one laptop demo.

Enterprise IT needs consistent enforcement across workstations. Fleetfold deploys with an agent and Credential Provider so every managed PC can require MFA at logon, with shared policies from your console.

Pair that with USB storage block so a successful sign-in does not become an easy path for removable-media exfiltration.

Windows fleet under Fleetfold Verify MFA policy

Self-hosted. Your keys stay yours.

Run the Fleetfold API and database on infrastructure you operate. Enrollment, secrets, and audit stay inside your boundary instead of a mandatory per-seat MFA cloud.

That matters for regulated teams, air-gapped-friendly designs, and buyers who will not outsource desktop access decisions.

Read the security model
Self-hosted Fleetfold Verify server and admin console

Operate from the Fleetfold console.

Enroll users, tune verified push, review challenges, and contain risk from a dedicated admin console. Operators see sign-in activity and policy without living in a generic SIEM screenshot.

Open admin console
Fleetfold Verify admin console dashboard

Retire password-only Windows access

Stand up Fleetfold on your infrastructure, enroll the first cohort, and make the next desktop logon prove identity with push or passcode.