FSSO Agent and multiple user logins
We have an issue with FSSO-based web filtering that I so far have been unable to solve:
We have the FSSO DC agents installed on all DCs. We have 4 AD groups set up, and we're using a guest profile set to Deny everything. Everything is working great, pulling in user logins, blocking sites, etc... Except for one thing. We have some users in our organization that either (1) Login from a PC with more than one username at a time, or (2) Admins will connect to other machines, either through CIFS/SMB shares or RDP using their 'Admin' accounts (our admins use a standard user account for day-to-day work activities). The issue is that when someone does this, the FSSO agent drops their normal user account from the list and adds the second account. Then when the second account logs off, it doesn't add the original account back, which means the first user account is now using the 'Guest' web filtering profile and they get blocked from all web sites. To get back on the "Logged on users" list, they have to basically lock their computer, then unlock it, which re-authenticates to Active Directory and the FSSO agent logs it and adds the account back to the list.
This is a major annoyance. This even impacts certain users who keep remote drives mapped using different credentials. Is there any way around this? It is making us re-think our entire setup.
