{"id":14758,"date":"2026-06-30T18:11:10","date_gmt":"2026-06-30T17:11:10","guid":{"rendered":"https:\/\/gatlabs.com\/knowledge\/?post_type=docs&#038;p=14758"},"modified":"2026-07-07T17:44:32","modified_gmt":"2026-07-07T16:44:32","password":"","slug":"gat-shield-plus-overview","status":"publish","type":"docs","link":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/","title":{"rendered":"GAT Shield+ Overview"},"content":{"rendered":"<h2>What is Shield+<\/h2>\n<p><b data-path-to-node=\"4\" data-index-in-node=\"0\">Shield+<\/b> is a Chrome extension paired with the SaaS service. Built as an enhanced evolution of GAT Shield, Shield+ acts as a frontline defense and monitoring hub directly within the user&#8217;s browser. Powered by sophisticated Machine Learning (ML) models and continuous identity verification, it bridges the gap between traditional endpoint security and real-time user behavior analytics.<\/p>\n<h3 data-path-to-node=\"5\">How it Works<\/h3>\n<p data-path-to-node=\"6\">Once deployed across your domain via Google Workspace or Chrome Enterprise management, Shield+ runs seamlessly on the user&#8217;s Chrome browser. It works by continuously evaluating security telemetry without disrupting the user experience:<\/p>\n<ul>\n<li data-path-to-node=\"7,0,0\"><b data-path-to-node=\"7,0,0\" data-index-in-node=\"0\">Continuous Identity Verification (ActiveID):<\/b> It analyzes the behavioral timing characteristics of a user&#8217;s typing patterns (never the actual words) to ensure the person behind the keyboard is the legitimate account owner.<\/li>\n<li data-path-to-node=\"7,1,0\"><b data-path-to-node=\"7,1,0\" data-index-in-node=\"0\">Proactive Policy Enforcement:<\/b> It monitors device performance, blocks phishing attempts via localized browser banners, and regulates copy\/paste behavior based on organizational compliance rules.<\/li>\n<li data-path-to-node=\"7,2,0\"><b data-path-to-node=\"7,2,0\" data-index-in-node=\"0\">Real-Time Visibility:<\/b> It feeds live browser data, alerts, and system health metrics directly back to the admin dashboard, allowing for instant incident response and session management.<\/li>\n<\/ul>\n<h3>Dashboard<\/h3>\n<p>Navigate to <strong>Shield+ &gt; Dashboard<\/strong> (the default view). It presents a summary of security alerts raised by the system&#8217;s Machine Learning models &#8211; the most important signal in the platform.<\/p>\n<p><strong>Time alerts<\/strong> &#8211; Three cards show alert counts; click on each to see more details<\/p>\n<ul>\n<li>Today &#8211; alerts from today<\/li>\n<li>Last 7 Days &#8211; alerts from the last 7 days<\/li>\n<li>All Time (Total) &#8211; overall total alerts<\/li>\n<\/ul>\n<p><strong>Alert types<\/strong> &#8211; Filter alert types<\/p>\n<ul>\n<li>All &#8211; all types of alerts combined<\/li>\n<li>ActiveID\/TypingID &#8211; alerts for ActiveID\/TypingID<\/li>\n<li>Inactivity Lock &#8211; Inactivity lock alerts<\/li>\n<li>Anti-Phishing &#8211; Anti-phishing alerts<\/li>\n<li>Device Performance &#8211; Device performance alerts<\/li>\n<\/ul>\n<p><strong>Scope &#8211; <\/strong>Used to select the users you want to view the dashboard for.<\/p>\n<ul>\n<li>Domain &#8211; select domain<\/li>\n<li>User &#8211; select a specific user<\/li>\n<li>Group &#8211; select a specific group<\/li>\n<li>Organization unit &#8211; select a specific org. unit<\/li>\n<\/ul>\n<h3>Daily Alerts Distribution<\/h3>\n<p>The daily alert distribution line chart shows alert volume over the past 30 days.<\/p>\n<p>Clicking any point on the chart navigates directly to the matching filtered alerts list. It can be expanded by zooming in\/out as well as downloaded as PNG, JPEG, or CSV.<\/p>\n<p>It can also be expanded to full screen and downloaded as such<\/p>\n<p>Navigate to <strong>Shield+ &gt; Dashboard<\/strong><\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-17768 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer.png\" alt=\"Dashboard Navigate to Shield+ and click on Dashboard (the default view). It presents a summary of security alerts raised by the system's Machine Learning models - the most important signal in the platform. Time alerts - Three cards show alert counts for Today - alerts from today\u00a0 Last 7 Days - alerts from the last 7 days All Time (Total) - overall total alerts\u00a0 Alert types - The alert types can be filtered for All - all types of alerts combined ActiveID\/TypingID - alerts for ActiveID\/TypingID only Inactivity Lock - Inactivity lock only Anti-Phishing - Anti-phishing alerts only\u00a0 Device Performance - Device performance alerts only\u00a0 Scope Dashboard\" width=\"1914\" height=\"844\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer.png 1914w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer-300x132.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer-1024x452.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer-768x339.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer-1536x677.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-12_43_44-Downloads-File-Explorer-360x159.png 360w\" sizes=\"(max-width: 1914px) 100vw, 1914px\" \/><\/p>\n<h2>Audit<\/h2>\n<p>The Audit section is a read-only section for logs and alert tables for every detection module for <strong>ActiveID<\/strong>, <strong>Device performance, Anti-Phishing,<\/strong> and <strong>Copy and Paste<\/strong><\/p>\n<h3>ActiveID &#8211; TypingID<\/h3>\n<h4><strong>TypingID<\/strong> <strong>Alerts<\/strong><\/h4>\n<p><strong>TypingID<\/strong> <strong>Alerts<\/strong> &#8211; A paginated table of every TypingID alert &#8211; events where the Machine Learning model determined, with confidence above the rule&#8217;s threshold, that the person typing is likely not the legitimate account owner. Each alert records the user, timestamp, confidence percentage, and current status.<\/p>\n<ul>\n<li>Severity can be updated, and alerts can be acknowledged individually or in bulk.<\/li>\n<li>Clicking an alert opens its details, which may include a screenshot, webcam capture, or the URL visited at the time, depending on the alert rule&#8217;s attachment configuration.<\/li>\n<\/ul>\n<h4><strong>TypingID<\/strong> <strong>Patterns<\/strong><\/h4>\n<p><strong>TypingID<\/strong> <strong>Patterns<\/strong> &#8211; The raw typing patterns collected from users and processed by the AI models. This view lets admins monitor how actively patterns are being generated per user, which directly reflects how well each user&#8217;s identity model is trained.<\/p>\n<ul>\n<li>We collect <strong>2 types of typing patterns<\/strong>. In this section, we present how many typing patterns were verified by our system on a daily basis.<\/li>\n<li>1st type patterns &#8211; <strong>Full Typing Pattern<\/strong> &#8211; A detailed profile pattern of your typing style based on 100\u2013150 keystrokes.<\/li>\n<li>View daily numbers &#8211; for the last 24 hrs<\/li>\n<li>View daily average &#8211; for the last 30 days<\/li>\n<li>2nd type patterns &#8211; <strong>Key-Pair Pattern<\/strong> &#8211; faster profiles built from the timing of consecutive letter pairs like &#8220;TH&#8221; or &#8220;AE&#8221;)<\/li>\n<li>View daily numbers &#8211; for the last 24 hrs<\/li>\n<li>View daily average &#8211; for the last 30 days<\/li>\n<\/ul>\n<p><strong>Scope<\/strong> &#8211; filter by user, domain, group, or org. unit.<\/p>\n<ul>\n<li><strong>Users protected<\/strong> &#8211; successfully built model means that the user is being actively protected. AI model checks if the generated text matches the user&#8217;s previous typing behaviour<\/li>\n<li><strong>Users without protection<\/strong> &#8211; list of users where this model is not built yet<\/li>\n<\/ul>\n<p>Navigate to <strong>Shield+ &gt; Audit &gt; ActiveID &gt; TypingID &gt; Alerts or Patterns<\/strong><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-17772 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12-.png\" alt=\"The ActiveID has typing and inactivity alerts TypingID TypingID Alerts - A paginated table of every TypingID alert - events where the Machine Learning model determined, with confidence above the rule's threshold, that the person typing is likely not the legitimate account owner. Each alert records the user, timestamp, confidence percentage, and current status. Aduit &gt; ActiveID &gt; TypingID &gt; Alerts or Patterns\" width=\"1904\" height=\"905\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12-.png 1904w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12--300x143.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12--1024x487.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12--768x365.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12--1536x730.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-15_33_12--360x171.png 360w\" sizes=\"(max-width: 1904px) 100vw, 1904px\" \/><\/p>\n<h4><strong>Inactivity Lock<\/strong><\/h4>\n<p><strong>Inactivity lock &#8211; Alerts<\/strong> are raised when an inactivity lock challenge is triggered, but the user failed to respond, responded incorrectly, or let the request time out. Each record shows the user, trigger time, and the specific failure reason (e.g., verification failed, timed out, credential not found).<\/p>\n<h4>Device performance<\/h4>\n<p><strong>Device performance<\/strong> is measured by the stats of alerts\u00a0raised when a user&#8217;s device CPU or memory usage exceeded a configured threshold for a sustained period. Each alert records the affected user, the resource (CPU or Memory), the metric (Maximum or Average), and the duration.<\/p>\n<ul>\n<li><strong>Alerts<\/strong> &#8211; Alerts are raised when a user&#8217;s device CPU or memory usage exceeds a configured threshold for a sustained period. Each alert records the affected user, the resource (CPU or Memory), the metric (Maximum or Average), and the duration.<\/li>\n<li><strong>Measurements<\/strong> &#8211; Raw performance readings collected from user devices over time. Individual records can be expanded to view CPU and memory measurement charts for a detailed history of a device&#8217;s resource usage.<\/li>\n<\/ul>\n<p>Navigate to <strong>Shield+ &gt; Audit &gt; Device performance &gt; Alerts or Measurements\u00a0<\/strong><\/p>\n<p><img decoding=\"async\" class=\"alignnone wp-image-17776 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer.png\" alt=\"Device performance Device performance is measured by the stats of alerts\u00a0raised when a user's device CPU or memory usage exceeded a configured threshold for a sustained period. Each alert records the affected user, the resource (CPU or Memory), the metric (Maximum or Average), and the duration. Alerts - Alerts are raised when a user's device CPU or memory usage exceeds a configured threshold for a sustained period. Each alert records the affected user, the resource (CPU or Memory), the metric (Maximum or Average), and the duration. Measurements - Raw performance readings collected from user devices over time. Audit &gt; Device performance &gt; Alerts or Measurements\u00a0\" width=\"1902\" height=\"891\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer.png 1902w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer-300x141.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer-1024x480.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer-768x360.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer-1536x720.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_32_21-Downloads-File-Explorer-360x169.png 360w\" sizes=\"(max-width: 1902px) 100vw, 1902px\" \/><\/p>\n<h4>Anti-Phishing<\/h4>\n<p><strong>Anti-Phishing Alerts<\/strong> \u2013 A paginated table of alerts generated by Anti-Phishing activity. Admins can review which user and URL were involved, when the event happened, which rule or policy applied, and the current alert status.<\/p>\n<p>This view is used to inspect Anti-Phishing outcomes such as blocked access or warning\/override events when browser enforcement is enabled. Admins can review alert details, update severity or status, acknowledge alerts, and decide whether a domain should be added to Allowed Websites or Blocked Websites.<\/p>\n<p>Allowed and Blocked Websites are configured under Security Configuration. The Audit view is for reviewing Anti-Phishing alerts, not managing those lists.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Audit &gt; Anti-Phishing &gt; Alerts\u00a0<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18083 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31-.png\" alt=\"Navigate to Shield+ &gt; Audit &gt; Anti-Phishing &gt; Alerts\u00a0\" width=\"1908\" height=\"825\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31-.png 1908w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31--300x130.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31--1024x443.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31--768x332.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31--1536x664.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-18_50_31--360x156.png 360w\" sizes=\"(max-width: 1908px) 100vw, 1908px\" \/><\/p>\n<h4>Copy \/ Paste<\/h4>\n<p>A log of all copy and paste events captured from users&#8217; browsers.<\/p>\n<p>Each entry shows the URL where the event occurred, the event type (Copy Allowed, Copy Blocked, Paste Allowed, Paste Blocked), and the user who triggered it.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Audit &gt; Copy\/Paste\u00a0<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17774 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17-.png\" alt=\"Copy \/ Paste has a log for all the events that occurred with this feature. View the event type as of if paste or copy was blocked along with details of where it has happend and when and by what users. Navigate to Shield+ &gt; Audit &gt; Copy\/Paste\u00a0\" width=\"1911\" height=\"865\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17-.png 1911w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17--300x136.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17--1024x464.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17--768x348.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17--1536x695.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_05_17--360x163.png 360w\" sizes=\"(max-width: 1911px) 100vw, 1911px\" \/><\/p>\n<p>The Admins can review flagged events, inspect details, and acknowledge alerts from these views.<\/p>\n<h2>Security Configuration<\/h2>\n<p>The Admins create and manage rules, policies, and lists that control how Shield+ detects threats and enforces actions.<\/p>\n<p>Changes here directly affect what gets flagged and what happens to users when a violation is detected.<\/p>\n<h3>ActiveID<\/h3>\n<p><strong>ActiveID<\/strong> is a feature of continuous typing verification. It creates a profile of a user based on typing characteristics. In order to create a profile, it will have to record the user&#8217;s typing patterns (but only timing characteristics, no actual words typed are recorded) for some time. Then it starts to verify every new pattern that comes to the app and decides whether it matches the profile or not. Based on the advanced logic of Machine Learning algorithms, it can decide whether the person who is typing is the actual user logged into their account or an imposter who gained unauthorised access to the account. In the latter case, the GAT Shield+ ActiveID feature will raise an alert, notifying the admin of the domain and (optionally) logging out the person who is typing from the account.<\/p>\n<h3>TypingID Rules<\/h3>\n<p>Create and manage the alert rules that govern when TypingID alerts fire. Each rule defines: the scope (which users it applies to), the prediction threshold (confidence level above which an alert is triggered), alert recipients and notification settings, optional alert attachments (screenshot, webcam capture, visited URL), and the action on violation &#8211; either no session action, a Passkey challenge (screen locked until the user verifies their identity), or clearing browser cookies (effectively ending all active sessions). Rules can be activated or deactivated without deleting them.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1912\" height=\"877\" class=\"alignnone size-full wp-image-17777\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46-.png\" alt=\"&quot;Create\" name=\"\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46-.png 1912w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46--300x138.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46--1024x470.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46--768x352.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46--1536x705.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-16_55_46--360x165.png 360w\" sizes=\"(max-width: 1912px) 100vw, 1912px\" \/><\/p>\n<h4>Create a typingID rule<\/h4>\n<p>Navigate to <strong>Shield+ &gt; Security configuration&gt; ActiveID &gt; TypingID &gt; Rules &gt; + New TypingID rule<\/strong><\/p>\n<ul>\n<li><strong>Name<\/strong> &#8211; enter the name for the rule\n<ul>\n<li>Default severity &#8211; select severity for the rule\n<ul>\n<li>Unspecified<\/li>\n<li>Low<\/li>\n<li>Moderate<\/li>\n<li>High<\/li>\n<li>Critical<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Scope<\/strong> &#8211; pick and select the scope for the alert\n<ul>\n<li>Pick user, group, or org. unit of users\n<ul>\n<li>Excluded scope &#8211; Specify users, groups, or OUs that should be excluded from the scope of the defined rule.\n<ul>\n<li>Add: excluded scope<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Configuration<\/strong> &#8211;\u00a0 Confidence level at which ActiveID will send an alert.\n<ul>\n<li><strong>Enter the prediction threshold<\/strong> (%) &#8211; add percentile<\/li>\n<li><strong>Action on violation<\/strong> &#8211; Select one of the user logout actions to be executed when a role is violated:\n<ul>\n<li>None &#8211; No user session action will be taken.<\/li>\n<li>Passkey -Locks the screen. Success resumes access; cancel or failure keeps the screen locked.<\/li>\n<li>Clear cookies -Clears browser cookies.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Notifications<\/strong> &#8211; fill in the details\n<ul>\n<li>Alert recipients &#8211; enter alert recipients<\/li>\n<li>Webhooks &amp; SIEM &#8211; select option\n<ul>\n<li>Elastic Search<\/li>\n<li>Generic receiver<\/li>\n<li>Splunk<\/li>\n<\/ul>\n<\/li>\n<li>Webcam capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Screen capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Attach website name &#8211; enable or disable the option<\/li>\n<\/ul>\n<\/li>\n<li><strong>Summary<\/strong> &#8211; view all the options that are selected<\/li>\n<\/ul>\n<h3>Inactivity Lock<\/h3>\n<h4>Scopes and Timers<\/h4>\n<p>Configure policies that define how long a user can be inactive before Shield+ requires identity verification in the browser. Each policy specifies the inactivity period in minutes and the scope of users it covers. When the inactivity threshold is reached, Shield+ requires the user to verify with Passkey before continuing.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Security configuration &gt; ActiveID &gt; Inactivity Lock &gt; Scopes and Timers &gt; New inactivity lock rule<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1905\" height=\"797\" class=\"alignnone wp-image-17778 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer.png\" alt=\"&quot;Name\" name=\"\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer.png 1905w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer-300x126.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer-1024x428.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer-768x321.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer-1536x643.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_17_49-Downloads-File-Explorer-360x151.png 360w\" sizes=\"(max-width: 1905px) 100vw, 1905px\" \/><\/p>\n<ul>\n<li><strong>Name<\/strong> &#8211; enter the name for the rule\n<ul>\n<li>Default severity &#8211; select severity for the rule\n<ul>\n<li>Unspecified<\/li>\n<li>Low<\/li>\n<li>Moderate<\/li>\n<li>High<\/li>\n<li>Critical<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Scope<\/strong> &#8211; pick and select the scope for the alert\n<ul>\n<li>Pick user, group, or org. unit of users\n<ul>\n<li>Excluded scope &#8211; Specify users, groups, or OUs that should be excluded from the scope of the defined rule.\n<ul>\n<li>Add: excluded scope<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Configuration<\/strong> &#8211;\u00a0<strong> Triggers an inactivity lock in the browser after a set period of user inactivity<\/strong>, such as 30 minutes away from the device. Unlike fixed schedules, it adapts to real behavior and activates only when the laptop is truly unattended.\n<ul>\n<li><strong>Defines the time period (in minutes) of screen inactivity before the inactivity lock is applied<\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18084 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings.png\" alt=\"Name - enter the name for the rule Default severity - select severity for the rule Unspecified Low Moderate High Critical Scope - pick and select the scope for the alert Pick user, group, or org. unit of users Excluded scope - Specify users, groups, or OUs that should be excluded from the scope of the defined rule. Add: excluded scope Configuration -\u00a0 Triggers an inactivity lock in the browser after a set period of user inactivity, such as 30 minutes away from the device. Unlike fixed schedules, it adapts to real behavior and activates only when the laptop is truly unattended. Defines the time period (in minutes) of screen inactivity before the inactivity lock is applied\" width=\"1873\" height=\"876\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings.png 1873w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings-300x140.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings-1024x479.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings-768x359.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings-1536x718.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_23_58-Settings-360x168.png 360w\" sizes=\"(max-width: 1873px) 100vw, 1873px\" \/><\/p>\n<ul>\n<li><strong>Notifications<\/strong> &#8211; fill in the details\n<ul>\n<li>Alert recipients &#8211; enter alert recipients<\/li>\n<li>Webhooks &amp; SIEM &#8211; select option\n<ul>\n<li>Elastic Search<\/li>\n<li>Generic receiver<\/li>\n<li>Splunk<\/li>\n<\/ul>\n<\/li>\n<li>Webcam capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Screen capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Attach website name &#8211; enable or disable the option<\/li>\n<\/ul>\n<\/li>\n<li><strong>Summary<\/strong> &#8211; view all the options that are selected<\/li>\n<\/ul>\n<h4>Website Exclusions<\/h4>\n<p>A list of website hosts excluded from immediate inactivity locking &#8211; intended for sites like video meetings, for example, <strong>meet.google.com<\/strong>, where users may be present without typing or moving the mouse.<\/p>\n<p>Entries are host names only, not full URLs.<\/p>\n<p>When a user on an excluded host reaches their inactivity period, Shield+ asks them to confirm they are still present before locking. If confirmed, the next inactivity check is deferred by the configured inactivity period, up to 30 minutes.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Security configuration &gt; ActiveID &gt; Inactivity Lock &gt;\u00a0 Website exclusions &gt; Add host<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17779 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27-.png\" alt=\"A list of website hosts excluded from the inactivity lock - intended for sites like video meetings (e.g. meet.google.com) where users are present but not actively typing. When a user on an excluded site reaches their inactivity period, Shield+ prompts them to confirm they're still there instead of locking immediately. Security configuration &gt; ActiveID &gt; Inactivity Lock &gt;\u00a0 Website exclusions\u00a0\" width=\"1909\" height=\"873\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27-.png 1909w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27--300x137.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27--1024x468.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27--768x351.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27--1536x702.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_24_27--360x165.png 360w\" sizes=\"(max-width: 1909px) 100vw, 1909px\" \/><\/p>\n<h3>Passkey &#8211; Credential management<\/h3>\n<p><span style=\"font-weight: 400;\">View and manage &#8220;Passkey&#8221; credentials registered by users for identity verification challenges. Admins can see which users have registered credentials, how many credentials they have, and when they were last used. Revoking credentials for a user forces that user to register a Passkey again on their next verification prompt.<\/span><\/p>\n<p>Passkey adds an extra identity check inside the Shield+ browser extension. It is used when the organization wants to make sure the person using the browser is still the correct user.<\/p>\n<p>Work for the end-user.<\/p>\n<ul>\n<li>The user is asked to set up a passkey.<\/li>\n<li>They can create it on this device, with a phone, or with a hardware security key.<\/li>\n<li>When Shield+ needs confirmation, the browser opens a security check screen.<\/li>\n<li>The user verifies with their passkey, device PIN, fingerprint, face unlock, phone, or security key.<\/li>\n<li>After successful verification, Shield+ returns the user to the page they were using.<\/li>\n<\/ul>\n<p>Shield+ does not store the user\u2019s password or biometric data. The device keeps the private part of the passkey. GAT\/Shield+ stores the registered credential information needed to check that future passkey responses are valid.<\/p>\n<p><b>When Passkey Is Used<\/b><\/p>\n<p>Passkey can be required in two main situations:<\/p>\n<ul>\n<li><b>Inactivity Lock<\/b><\/li>\n<\/ul>\n<p>If the user has been inactive for a configured number of minutes,<strong> Shield+ locks browsing<\/strong> and <strong>asks for passkey verification before the user can continue.<\/strong><\/p>\n<ul>\n<li><b>ActiveID Check<\/b><\/li>\n<\/ul>\n<p>If ActiveID detects unusual typing behavior, an administrator can configure the response to require passkey verification. This helps reduce false positives: instead of immediately treating the activity as unauthorized, the user can prove they are really present.<\/p>\n<p>There is also an administrator-forced security check path in the extension, but the main user-facing configuration is Inactivity Lock and ActiveID Passkey action.<\/p>\n<p><b>Administrator Configuration<\/b><\/p>\n<p>Navigate to <strong>Security configuration &gt; ActiveID &gt; TypingID &gt; Rules &gt; New TypingID rule\u00a0<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18085 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04-.png\" alt=\"Navigate to Security configuration &gt; ActiveID &gt; TypingID &gt; Rules &gt; New TypingID rule\u00a0\" width=\"1911\" height=\"879\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04-.png 1911w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04--300x138.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04--1024x471.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04--768x353.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04--1536x707.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_27_04--360x166.png 360w\" sizes=\"(max-width: 1911px) 100vw, 1911px\" \/><\/p>\n<div class=\"q-pb-sm text-weight-medium\">Select one of the user logout actions to be executed when a role is violated:<\/div>\n<div class=\"q-pb-xs\">\n<div class=\"q-chip row inline no-wrap items-center bg-surface-3 text-primary-1 q-chip--colored text-weight-medium ellipsis q-px-sm\">\n<ul>\n<li class=\"q-chip__content col row no-wrap items-center q-anchor--skip\"><strong>None<\/strong> -No user session action will be taken.<\/li>\n<li class=\"q-chip__content col row no-wrap items-center q-anchor--skip\"><strong>Passkey<\/strong> &#8211; Locks the screen. Success resumes access; cancel or failure keeps the screen locked.<\/li>\n<li class=\"q-chip__content col row no-wrap items-center q-anchor--skip\"><strong>Clear cookies<\/strong> &#8211; Clears browser cookies.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h5><b>First-Time User Experience: <\/b><\/h5>\n<p>If a user is asked to verify but has no passkey yet, Shield+ sends them to the passkey setup page.<\/p>\n<p>After setup, they can use the passkey for future security checks. If the user later adds another passkey, Shield+ may ask them to verify first.<\/p>\n<p>Set up passkey as follows.<\/p>\n<ul>\n<li>Create on this device &#8211; create for the device itself<\/li>\n<li>Create with phone &#8211; barcode will be generated, then scanned with mobile phone<\/li>\n<li>Create with security key &#8211; use USB to create passkey<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18086\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_31_46-.png\" alt=\"\" width=\"672\" height=\"591\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_31_46-.png 672w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_31_46--300x264.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_31_46--360x317.png 360w\" sizes=\"(max-width: 672px) 100vw, 672px\" \/><\/p>\n<h4 data-path-to-node=\"5\">What the Admin Controls<\/h4>\n<p data-path-to-node=\"5\">From the admin console, you manage the passkeys.<\/p>\n<ul>\n<li><b data-path-to-node=\"7,0,0\" data-index-in-node=\"0\">Visibility:<\/b> You can see a list of all Passkeys registered by your users, along with exactly when they were last used to unlock a browser.<\/li>\n<li><b data-path-to-node=\"7,1,0\" data-index-in-node=\"0\">Revoking Access:<\/b> If a user loses a hardware key or if you suspect a security breach, you can instantly revoke an individual passkey or wipe all passkeys for that user.<\/li>\n<\/ul>\n<h3><strong>Anti-Phishing<\/strong><\/h3>\n<p>Create and manage Anti-Phishing alert rules. Each rule defines the scope, notification recipients, and browser action settings for detector results. Admins can choose whether detector warnings and blocking should interrupt the user in the browser, and can configure the severity threshold at which detector block results become hard blocks. Administrator-blocked websites are always blocked by policy.<\/p>\n<p><strong>Rules &#8211;\u00a0<\/strong>Define and create new anti-phishing rules.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Security configuration &gt; Anti-Phishing &gt; New anti-phishing rule<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1894\" height=\"837\" class=\"alignnone wp-image-17781 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00-.png\" alt=\"&quot;Name\" name=\"\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00-.png 1894w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00--300x133.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00--1024x453.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00--768x339.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00--1536x679.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_34_00--360x159.png 360w\" sizes=\"(max-width: 1894px) 100vw, 1894px\" \/><\/p>\n<ul>\n<li><strong>Name<\/strong> &#8211; enter the name for the rule\n<ul>\n<li>Default severity &#8211; When the Alert Rule is triggered, a notification is created. The severity of the notification is decided by the software and indicates its level of importance. The values are Low, Moderate, High, and Critical. &#8220;Alert Level Threshold&#8221; is the &#8220;notification threshold&#8221;. If you set the default severity to &#8220;Low,&#8221; it means that &#8220;all alerts with severity level Low and higher will be sent&#8221;.\n<ul>\n<li>Unspecified<\/li>\n<li>Low<\/li>\n<li>Moderate<\/li>\n<li>High<\/li>\n<li>Critical<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Scope<\/strong> &#8211; pick and select the scope for the alert\n<ul>\n<li>Pick user, group, or org. unit of users\n<ul>\n<li>Excluded scope &#8211; Specify users, groups, or OUs that should be excluded from the scope of the defined rule.\n<ul>\n<li>Add: excluded scope<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><strong>Configuration<\/strong> &#8211;\u00a0 Admin will be alerted by default; in addition, Shield+ can block the site inside the user&#8217;s browser if the setting below is enabled.\n<ul>\n<li><strong>Show detector warnings\/blocking<\/strong> \u2013 When enabled, detector results can interrupt the user in the browser. Warning results show a user-visible warning that can be overridden. Detector block results become hard blocks only at or above the configured hard-block threshold; below that threshold, they behave as overridable warnings. Administrator-blocked websites are always blocked.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18087 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings.png\" alt=\"Name - enter the name for the rule\nDefault severity - When the Alert Rule is triggered, a notification is created. The severity of the notification is decided by the software and indicates its level of importance. The values are Low, Moderate, High, and Critical. &quot;Alert Level Threshold&quot; is the &quot;notification threshold&quot;. If you set the default severity to &quot;Low,&quot; it means that &quot;all alerts with severity level Low and higher will be sent&quot;.\nUnspecified\nLow\nModerate\nHigh\nCritical\nScope - pick and select the scope for the alert\nPick user, group, or org. unit of users\nExcluded scope - Specify users, groups, or OUs that should be excluded from the scope of the defined rule.\nAdd: excluded scope\nConfiguration -\u00a0 Admin will be alerted by default; in addition, Shield+ can block the site inside the user's browser if the setting below is enabled.\nShow detector warnings\/blocking \u2013 When enabled, detector results can interrupt the user in the browser. Warning results show a user-visible warning that can be overridden. Detector block results become hard blocks only at or above the configured hard-block threshold; below that threshold, they behave as overridable warnings. Administrator-blocked websites are always blocked.\" width=\"1861\" height=\"1035\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings.png 1861w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings-300x167.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings-1024x570.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings-768x427.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings-1536x854.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_38_03-Settings-360x200.png 360w\" sizes=\"(max-width: 1861px) 100vw, 1861px\" \/><\/p>\n<ul>\n<li><strong>Notifications<\/strong> &#8211; fill in the details\n<ul>\n<li>Alert recipients &#8211; enter alert recipients<\/li>\n<li>Webhooks &amp; SIEM &#8211; select option\n<ul>\n<li>Elastic Search<\/li>\n<li>Generic receiver<\/li>\n<li>Splunk<\/li>\n<\/ul>\n<\/li>\n<li>Webcam capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Screen capture &#8211; select option\n<ul>\n<li>Do not send<\/li>\n<li>Send in the notification email<\/li>\n<li>Send in the notification email and save to the rule creator&#8217;s Drive<\/li>\n<li>Send in the notification email, save to the rule creator&#8217;s Drive, and share with other alert recipients<\/li>\n<\/ul>\n<\/li>\n<li>Attach website name &#8211; enable or disable the option<\/li>\n<\/ul>\n<\/li>\n<li><strong>Summary<\/strong> &#8211; view all the options that are selected<\/li>\n<\/ul>\n<h3>Allowed Websites \/ Blocked Websites<\/h3>\n<p>Domains manually added by admins to control Anti-Phishing behavior.<\/p>\n<p>Allowed Websites are trusted domains where pages bypass Anti-Phishing checks and can override administrator-blocked domain entries. Blocked Websites are domains that are always treated as phishing threats and blocked for users by administrator policy.<\/p>\n<p>Entries are saved as site domains. The current UI accepts domains only. Protocols, ports, paths, and wildcards are not accepted in these fields.<\/p>\n<p>Allowed Websites: Add a domain that should be trusted by Anti-Phishing protection.<\/p>\n<p>Valid format:<\/p>\n<ul>\n<li>example.com \u2192 Bypasses Anti-Phishing checks for pages on this site<\/li>\n<\/ul>\n<p>Blocked Websites: Add a domain that should always be treated as a phishing threat by Anti-Phishing protection.<\/p>\n<p>Valid format:<\/p>\n<ul>\n<li>example.com \u2192 Blocks pages on this site by administrator policy<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18088\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot.png\" alt=\"\" width=\"1897\" height=\"714\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot.png 1897w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot-300x113.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot-1024x385.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot-768x289.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot-1536x578.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-07-07-19_43_11-Greenshot-360x135.png 360w\" sizes=\"(max-width: 1897px) 100vw, 1897px\" \/><\/p>\n<h4>Device Performance &#8211; Performance Rules<\/h4>\n<p>Set up a performance rule for the device resource monitoring. Each rule can specify a performance source; it can be CPU or Memory, the metric (Maximum or Average readings), the timeframe the condition must hold (15, 30, or 60 minutes), the threshold percentage, and notification recipients.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Security configuration &gt; Device performance &gt; New perormance rule<\/strong><\/p>\n<p>Fill in the required details such as Source, Metric, and Time condition<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17785\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23-.png\" alt=\"\" width=\"1906\" height=\"879\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23-.png 1906w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23--300x138.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23--1024x472.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23--768x354.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23--1536x708.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-17_56_23--360x166.png 360w\" sizes=\"(max-width: 1906px) 100vw, 1906px\" \/><\/p>\n<h4>Copy \/ Paste<\/h4>\n<p>Configure copy and paste restrictions across the domain.<\/p>\n<p>Two modes: Allow All (copy\/paste permitted everywhere by default &#8211; specific URLs can be added to block) or Block All (copy\/paste denied everywhere by default &#8211; specific URLs can be added to allow).<\/p>\n<p>URL entries support wildcards ending with `\/*` to cover child paths.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Security configuration &gt; Copy \/ Paste &gt; New copy\/paste rule<\/strong><\/p>\n<ul>\n<li>Allow all &#8211; by default, all URLs are allowed by default\n<ul>\n<li>Add websites so the block of copy\/paste is enabled only on those websites.<\/li>\n<\/ul>\n<\/li>\n<li>Block all &#8211; you can block all and allow copy\/paste on some sites<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1896\" height=\"840\" class=\"alignnone wp-image-17786 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot.png\" alt=\"&quot;Navigate\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot.png 1896w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot-300x133.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot-1024x454.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot-768x340.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot-1536x681.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_02_01-Greenshot-360x159.png 360w\" sizes=\"(max-width: 1896px) 100vw, 1896px\" \/><\/p>\n<h2>Monitoring<\/h2>\n<p>Real-time visibility into users&#8217; Chrome browser activity. The monitored user&#8217;s browser always displays a visible indicator that monitoring is active.<\/p>\n<blockquote><p>(Note, the user browser will indicate that it is being actively monitored.)<\/p><\/blockquote>\n<h3>Browser Monitoring<\/h3>\n<p>The Admin can view one or more users&#8217; live browser screens in real time. After selecting a monitoring target (user, group, or OU), the admin sees thumbnails of all open tabs and windows. Available tab actions: switch the user to a specific tab, open a new tab for the user at a given URL, close a tab on the user&#8217;s behalf, or open a copy of the tab in the admin&#8217;s own browser.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Monitoring &gt; Browser monitoring &gt; Scope &#8211; select the scope of users to monitor<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17787\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55-.png\" alt=\"\" width=\"1914\" height=\"833\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55-.png 1914w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55--300x131.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55--1024x446.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55--768x334.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55--1536x668.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_16_55--360x157.png 360w\" sizes=\"(max-width: 1914px) 100vw, 1914px\" \/><\/p>\n<h3>Monitoring Groups<\/h3>\n<p>Pre-configured groups that delegate browser monitoring authority to supervisors or managers without requiring admin involvement each time.<\/p>\n<p>Each group defines Targets (users whose browsers can be monitored) and Auditors (people permitted to start monitoring sessions). Once a group is set up, any assigned auditor can initiate monitoring directly from the group&#8217;s page.<\/p>\n<p>Navigate to <strong>Shield+ &gt; Monitoring &gt; Monitoring groups &gt; New monitoring group<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17788 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55-.png\" alt=\"Pre-configured groups that delegate browser monitoring authority to supervisors or managers without requiring admin involvement each time. Monitoring &gt; Monitoring groups &gt; New monitoring group\" width=\"1901\" height=\"898\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55-.png 1901w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55--300x142.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55--1024x484.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55--768x363.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55--1536x726.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_20_55--360x170.png 360w\" sizes=\"(max-width: 1901px) 100vw, 1901px\" \/><\/p>\n<h2>Webhooks &amp; SIEM<\/h2>\n<p>Forwards Shield+ security events to external systems such as SIEM platforms, log aggregators, or custom webhook endpoints.<\/p>\n<ul>\n<li><strong>Sinks<\/strong> &#8211; Configure the outbound destinations where Shield+ delivers event payloads. A Sink is a named endpoint (webhook URL or SIEM receiver) that accepts incoming events.<\/li>\n<li><strong>Triggers<\/strong> -Rules that map specific Shield+ event types (e.g., TypingID alert, anti-phishing block, inactivity lock) to specific Sinks. Controls which events get forwarded where.<\/li>\n<li><strong>Logs<\/strong> &#8211; A delivery log of all outbound SIEM and webhook events: what was sent, the destination Sink, and the timestamp.<\/li>\n<\/ul>\n<p>Navigate to <strong>Shield+ &gt; Webhooks &amp; SIEMs &gt; New Sink &gt; New Sink<\/strong><\/p>\n<p>Fill in the details. Choose the receiving Sink system (e.g., SIEM) and configure credentials. Depending on the type of the receiver system, you need to provide the full URL and either an authorization token or a set of HTTP headers to be included in every request.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1918\" height=\"859\" class=\"alignnone wp-image-17789 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot.png\" alt=\"&quot;Forwards\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot.png 1918w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot-300x134.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot-1024x459.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot-768x344.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot-1536x688.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_25_31-Greenshot-360x161.png 360w\" sizes=\"(max-width: 1918px) 100vw, 1918px\" \/><\/p>\n<h2>Delegated Auditors<\/h2>\n<p>Delegate Shield+ audit access to users who are not domain administrators. Auditors can be granted access to specific feature areas &#8211; ActiveID, Anti-Phishing, Device Performance, Copy\/Paste, Browser Monitoring, or Webhooks &amp; SIEM &#8211; and optionally scoped to a specific set of users, groups, or organizational units, so each auditor sees only the data relevant to their team.<\/p>\n<p><strong>Navigate to Shield+ &gt; Delegated auditor<\/strong><\/p>\n<p>Fill in the details, select the scope type, who will be the auditor, and the scope &#8211; what users will be monitored<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"1913\" height=\"874\" class=\"alignnone wp-image-17790 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09-.png\" alt=\"&quot;Navigate\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09-.png 1913w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09--300x137.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09--1024x468.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09--768x351.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09--1536x702.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-30-18_30_09--360x164.png 360w\" sizes=\"(max-width: 1913px) 100vw, 1913px\" \/><\/p>\n<h3>Configuration<\/h3>\n<p>Admin-only settings for the Shield+ deployment.<\/p>\n<p>Manage the deployment of the Shield+ browser extension across the domain. The extension is installed on user machines and is the component that collects typing patterns, enforces copy\/paste policies, enables browser monitoring, and displays anti-phishing blocking pages.<\/p>\n<h3>Admin Log<\/h3>\n<p>A complete audit trail of all administrative actions taken within Shield+: logins, creation, update, and deletion of alert rules and policies, browser monitoring session starts and stops, configuration changes, and data exports.<\/p>\n<p>Each entry records the responsible administrator, the timestamp, and the full details of every change, including before-and-after comparisons where applicable.<\/p>\n<h2 data-path-to-node=\"11\">Conclusion: Why Shield+ is Essential for Your Enterprise<\/h2>\n<p data-path-to-node=\"12\">Managing security across a distributed enterprise domain requires visibility that goes beyond static firewalls and standard login prompts. <b data-path-to-node=\"12\" data-index-in-node=\"139\">Shield+<\/b> delivers this exact layer of deep, behavioral protection right at the edge &#8211; inside the browser where your users spend their workday.<\/p>\n<h2 data-path-to-node=\"13\">Key Benefits for Enterprise Admins<\/h2>\n<ul>\n<li data-path-to-node=\"14,0,0\"><b data-path-to-node=\"14,0,0\" data-index-in-node=\"0\">Zero-Trust Identity Protection:<\/b> By utilizing Machine Learning to flag anomalous typing patterns and enforcing Passkey or session-termination challenges, Shield+ stops active session hijacking and insider threats in their tracks.<\/li>\n<li data-path-to-node=\"14,1,0\"><b data-path-to-node=\"14,1,0\" data-index-in-node=\"0\">Granular Data &amp; Compliance Control:<\/b> From blocking malicious URLs out-of-the-box to restricting copy\/paste data leaks on sensitive websites, you have complete control over data movement.<\/li>\n<li data-path-to-node=\"14,2,0\"><b data-path-to-node=\"14,2,0\" data-index-in-node=\"0\">Operational Efficiency:<\/b> The platform shifts your team from reactive auditing to proactive management. With real-time browser monitoring, automated alerts, delegated access for team managers, and seamless SIEM\/Webhook integration (Splunk, Elastic Search, etc.), security incidents are localized, logged, and mitigated instantly.<\/li>\n<\/ul>\n<p data-path-to-node=\"15\">By deploying Shield+, you aren\u2019t just monitoring your enterprise domain; you are actively hardening it against the modern threat landscape while maintaining full visibility and administrative control.<\/p>\n<h2 data-path-to-node=\"15\">Related Posts<\/h2>\n<ul>\n<li>\n<p id=\"betterdocs-entry-title\" class=\"betterdocs-entry-title\"><a href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-installation\/\" target=\"_blank\" rel=\"noopener\">How to install GAT Shield+<\/a><\/p>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>What is Shield+ Shield+ is a Chrome extension paired with the SaaS service. Built as an enhanced evolution of GAT Shield, Shield+ acts as a frontline defense and monitoring hub directly within the user&#8217;s browser. Powered by sophisticated Machine Learning (ML) models and continuous identity verification, it bridges the gap between traditional endpoint security and [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":17799,"comment_status":"open","ping_status":"closed","template":"","meta":{"footnotes":""},"doc_category":[18],"glossaries":[],"doc_tag":[91],"class_list":["post-14758","docs","type-docs","status-publish","has-post-thumbnail","hentry","doc_category-products-overview","doc_tag-shield"],"year_month":"2026-07","word_count":3918,"total_views":"243","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"stan","author_nicename":"stan","author_url":"https:\/\/gatlabs.com\/knowledge\/author\/stan\/"},"doc_category_info":[{"term_name":"Products Overview","term_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips-category\/products-overview\/"}],"doc_tag_info":[{"term_name":"Shield+","term_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips-tag\/shield\/"}],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>GAT Shield+ Overview - GAT Knowledge Base<\/title>\n<meta name=\"description\" content=\"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GAT Shield+ Overview\" \/>\n<meta property=\"og:description\" content=\"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/\" \/>\n<meta property=\"og:site_name\" content=\"GAT Knowledge Base\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-07T16:44:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/gat-shield-6a43f2c2e702d.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1800\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"21 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/\",\"name\":\"GAT Shield+ Overview - GAT Knowledge Base\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/gat-shield-6a43f2c2e702d.webp\",\"datePublished\":\"2026-06-30T17:11:10+00:00\",\"dateModified\":\"2026-07-07T16:44:32+00:00\",\"description\":\"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/#primaryimage\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/gat-shield-6a43f2c2e702d.webp\",\"contentUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/gat-shield-6a43f2c2e702d.webp\",\"width\":1800,\"height\":900,\"caption\":\"Shield+\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/gat-shield-plus-overview\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tech Tips\",\"item\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"GAT Shield+ Overview\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#website\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\",\"name\":\"GAT Knowledge Base\",\"description\":\"Your source of all things GAT\",\"publisher\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#organization\",\"name\":\"GAT Labs Knowledge Base\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Group-1159.svg\",\"contentUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Group-1159.svg\",\"width\":361,\"height\":97,\"caption\":\"GAT Labs Knowledge Base\"},\"image\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GAT Shield+ Overview - GAT Knowledge Base","description":"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/","og_locale":"en_GB","og_type":"article","og_title":"GAT Shield+ Overview","og_description":"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.","og_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/","og_site_name":"GAT Knowledge Base","article_modified_time":"2026-07-07T16:44:32+00:00","og_image":[{"width":1800,"height":900,"url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/gat-shield-6a43f2c2e702d.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_misc":{"Estimated reading time":"21 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/","url":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/","name":"GAT Shield+ Overview - GAT Knowledge Base","isPartOf":{"@id":"https:\/\/gatlabs.com\/knowledge\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/#primaryimage"},"image":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/#primaryimage"},"thumbnailUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/gat-shield-6a43f2c2e702d.webp","datePublished":"2026-06-30T17:11:10+00:00","dateModified":"2026-07-07T16:44:32+00:00","description":"Explore GAT Shield+. Learn more about ActiveID, browser monitoring, anti-phishing protection, passkey authentication, copy and paste controls, and SIEM integration.","breadcrumb":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/#primaryimage","url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/gat-shield-6a43f2c2e702d.webp","contentUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/gat-shield-6a43f2c2e702d.webp","width":1800,"height":900,"caption":"Shield+"},{"@type":"BreadcrumbList","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/gat-shield-plus-overview\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gatlabs.com\/knowledge\/"},{"@type":"ListItem","position":2,"name":"Tech Tips","item":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/"},{"@type":"ListItem","position":3,"name":"GAT Shield+ Overview"}]},{"@type":"WebSite","@id":"https:\/\/gatlabs.com\/knowledge\/#website","url":"https:\/\/gatlabs.com\/knowledge\/","name":"GAT Knowledge Base","description":"Your source of all things GAT","publisher":{"@id":"https:\/\/gatlabs.com\/knowledge\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gatlabs.com\/knowledge\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/gatlabs.com\/knowledge\/#organization","name":"GAT Labs Knowledge Base","url":"https:\/\/gatlabs.com\/knowledge\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/gatlabs.com\/knowledge\/#\/schema\/logo\/image\/","url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2021\/11\/Group-1159.svg","contentUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2021\/11\/Group-1159.svg","width":361,"height":97,"caption":"GAT Labs Knowledge Base"},"image":{"@id":"https:\/\/gatlabs.com\/knowledge\/#\/schema\/logo\/image\/"}}]}},"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/14758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/comments?post=14758"}],"version-history":[{"count":30,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/14758\/revisions"}],"predecessor-version":[{"id":18089,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/14758\/revisions\/18089"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/media\/17799"}],"wp:attachment":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/media?parent=14758"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/doc_category?post=14758"},{"taxonomy":"glossaries","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/glossaries?post=14758"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/doc_tag?post=14758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}