Skip to main content

Function Specification Document

Last updated: 2026.06.08

RFP Notation Standards

NotationmeaningExplanation
EssentialCommon Evaluation CriteriaRequired Features Typically Requested in Web Isolation (RBI) Business RFP
specializationDifferentiation ItemsUnique feature of SHIELD Gate that provides an advantage over competitors — Recommended to add evaluation criteria to the RFP.
SelectionAdditional ItemsFeatures proposed optionally based on customer requirements
Major CategoryMid-categorysub-categoryDetailed DescriptionRFP notationspec
Home ScreenStatus DashboardSecurity365 StatusAt the top of the dashboard, you can see the overall status at a glance • Users: Total number of registered users • Administrators: Number of users with management privileges • Groups: Total number of basic groups + policy groups • Condition Items: Number of registered condition items such as location, time, country, etc.Essentiallink
Home ScreenStatus DashboardSubscription Service StatusYou can check the service name, license type, subscription status, and expiration date of your subscription. • Subscription status: Trial / Active / Expiring soon (within 30 days) / Expired • Non-subscribed services are displayed as introduction cards,자세히Check details with the buttonSelectionlink
Home ScreenStatus DashboardActual User StatusYou can check the actual user trends by product in a chart.Selectionlink
Home ScreenStatus DashboardAccount Synchronization StatusDisplay Microsoft365·SCI Server synchronization information in card format • Method·Cycle·Start Time·Status·Check the date and time of the last synchronization • If there is no synchronization history계정 동기화 설정Button Display • Move directly to synchronization settings with the button in the upper right corner of the cardSelectionlink
Home ScreenService MigrationMove to Management CenterClicking the service name at the bottom of the left menu will directly move to the corresponding service admin page (relay token method)Selectionlink
User ManagementUser Registration and IntegrationManual Registration and CSV UploadUser individual registration or CSV bulk registration available • CSV template provided • Activation status default: Inactive • When uploading large volumes (over 200,000 records), only summary information is displayed to prevent browser freezeEssentiallink
User ManagementUser Registration and IntegrationCSV Bulk Registration Processing OptionsYou can choose to deactivate or retain existing users not present in the CSV during bulk registration. • Supports downloading the processing result CSV (including CREATED / UPDATED / UNCHANGED status values) • Original file can be downloaded from the job history • Asynchronous processing — other menus can be used while in progress.specializationlink
User ManagementUser Registration and IntegrationAccount SynchronizationMicrosoft365·SCI Server integration allows for automatic user registration • Microsoft365: Choose between full synchronization or synchronization of specified AD groups (security/mail group type) • SCI Server: Supports domain conversion settings if the ID is not in email formatEssentiallink
User ManagementUser Activation ManagementUser Activation/Deactivation ControlControl the user's service access availability in an active state • Automatically record reasons when deactivated (automatic deactivation, CSV synchronization, manual by administrator)Essentiallink
User ManagementUser Activation ManagementAutomatic Logging of Deactivation ReasonsAutomatically display the reason for account deactivation on the detail screen • Deactivation paths: Automatic deactivation / CSV synchronization / Manual by administrator • Automatically reset the reason upon activationspecializationlink
User ManagementUser Activation ManagementBulk Enable/Disable Search ResultsYou can enable or disable users in bulk based on search and filter results • Supports bulk processing after searching by groupspecialization-
User ManagementUser QueryDisplay Last Access InformationDisplay last access column in user list (relative time format, sortable) • Check exact access date and time on mouse over • Include column in downloaded fileEssentiallink
User ManagementUser QueryDisconnected Period FilterFiltering long-term inactive users for 7·30·60·90 days or more or direct input • The last access column is automatically included in the downloaded file when the filter is applied.specializationlink
User ManagementManagement HistoryBatch Registration Task History InquiryYou can check the executor, status, and processing result statistics of the user batch registration task and download the original file. • Status: In Registration / Partially Registered / Registration Complete / Not Processed • You can check the number of new creations, updates, no changes, deletions, and maintenance.specializationlink
User ManagementPassword Reset SupportSend Email LinkSend password reset link to user email (valid for 10 minutes) • Multiple users can be selected for bulk sending.Essentiallink
User ManagementPassword Reset SupportTemporary Password IssuanceThe administrator generates a temporary password and delivers it to the user • Single user target • The user can log in with the provided temporary password and change it to a new password.Essentiallink
User ManagementPassword Reset SupportBulk Password ResetBulk reset of passwords for all users in the tenant**(On-Premise Only)**• Always exclude own account • Optional exclusion of administrator (ADMIN) role (default: exclude) • Provide option to force password change on next login • Asynchronous processing (may take a few minutes for large tenants)specialization-
User ManagementDownloadDownload User ListYou can download all or selected user information as a CSV file.Essentiallink
User ManagementList SettingsSetting items to display in the listCustomizable settings for table column visibility and order • Select columns displayed with checkboxes • Change order with drag and dropSelectionlink
User ManagementBackup and RestoreManual Backup CreationManual backup of current user and group data to a specific point in timespecializationlink
User ManagementBackup and RestoreData Restoration (Rollback)Restore data to the selected backup point • Preview of changes before restoration • Automatic backup of the current state just before restorationspecializationlink
User ManagementBackup and RestoreCSV Synchronization Automatic BackupAutomatic backup of current user and group data when executing CSV bulk registration or remote synchronization • Display a guidance slide for choosing whether to proceed in case of backup failurespecialization-
Administrator ManagementSetting Up Administrator RolesAdministrator Permission Classification4 Roles for Function Access Permission Segmentation • Super Administrator: Full access to all functions • Edit Administrator: View and edit access • View Administrator: View-only access • Log View Administrator: Log-only access (System monitoring menu not displayed)Essentiallink
Administrator ManagementSetting Up Administrator RolesAdmin Notification SettingsIt is possible to set up real-time notification sending to a specified email when the log viewer administrator logs in or logs out.Selectionlink
Administrator ManagementAdministrator Access PolicyAdministrator Access Policy SettingsAccess to the administrator's admin page can be restricted based on conditions such as IP and time • Priority-based multi-policy managementEssentiallink
Administrator ManagementAdministrator Access PolicyAdditional Authentication SettingsAdministrator access may require OTP or additional email authentication.Essentiallink
Group ManagementBasic GroupManual Registration and CSV UploadGroup individual registration or CSV bulk registration available • CSV template provided • Hierarchical structure (ParentGroupId) supported • GroupName·GroupId required inputEssentiallink
Group ManagementBasic GroupCSV Bulk Registration Processing OptionsYou can choose how to handle existing groups that are not in the CSV during bulk registration. • Delete: Only empty groups (groups without members) will be automatically deleted. • Maintain: Keep the existing group status as is (recommended during the first synchronization or partial updates).specializationlink
Group ManagementBasic GroupAccount SynchronizationMicrosoft 365·SCI Server integration allows for automatic group registration • Supported group types: Security group·Mail groupEssentiallink
Group ManagementPolicy GroupManual RegistrationGroup individual registration available • Users can be combined as members of the default group • Members can be added through general search (manual selection) or conditional search (automatic filtering)Essentiallink
Group ManagementPolicy GroupCondition-Based Group SettingsPolicy group creation possible with users filtered by condition • New users matching conditions automatically added during Microsoft365 synchronization • Multiple conditions can be combined using AND methodspecializationlink
Group ManagementManagement HistoryBatch Registration Task History InquiryYou can view the executor, status, and processing result statistics of the group batch registration task and download the original file.specializationlink
Group ManagementDownloadDownload Group ListYou can download the information of the entire group or selected groups as a CSV file.Essentiallink
License ManagementStatus MonitoringCheck License StatusYou can check the status of the subscribed plan, total number of licenses, allocation, and remaining status.Essentiallink
License ManagementLicense AssignmentManual Allocation/DeallocationUser search allows for individual or bulk license assignment and revocation •모든 사용자 추가Batch assignment possible for all users activated by the button • Warning notification displayed when exceeding remaining licensesEssentiallink
License ManagementLicense AssignmentAutomatic Assignment SettingsAutomatic license assignment upon user activation, automatic release upon deactivation or deletion • Choose from 2 modes: Assign including existing active users / Assign only to users activated laterspecializationlink
Conditional Policy ManagementService Access PolicyBasic Authentication PolicyAccess Allowance or Blocking Settings for Users and Groups by Service • Additional OTP or email authentication may be required when access is allowed • If "Do not use" is selected, access is granted only with ID and passwordEssentiallink
Conditional Policy ManagementService Access PolicyConditional Access PolicyIP·Time·Country·Device conditions-based access control settings • Multiple conditions can be specified, AND·OR method selection • Additional authentication via OTP·Email may be required when access is grantedEssentiallink
Conditional Policy ManagementService Access PolicyAdditional Authentication SettingsAccess may require additional OTP and email verification when allowed • If "Do not use" is selected, access is permitted with only the ID and password.Essentiallink
Conditional Policy ManagementService Access PolicyAdvanced Search and SortingPolicy name and the ability to search for multiple conditions such as members, targets, services, and usage status • AND structure between conditions / OR structure within conditions • After clicking on the policy, you can move to the desired priority location.specialization-
Conditional Policy ManagementService Access PolicyConditional Policy Excel DownloadYou can download the list of conditional policies as an Excel file.specialization-
Condition Item ManagementRegister Condition ItemsLocation (IP) ConditionSingle IP, IP range, IP scope conditions can be registered.Essentiallink
Condition Item ManagementRegister Condition ItemsCountry ConditionsRegistration of access conditions based on country code is possible.Selectionlink
Condition Item ManagementRegister Condition ItemsTime ConditionStart and end time, day-based access condition registration availableEssentiallink
Security Classification Label ManagementGrade ManagementGrade Creation/Modification/DeletionSecurity level grade (confidential, sensitive, public, etc.) creation and color setting possible • Utilized for policy tagging and data classification in each serviceSelectionlink
Security Classification Label ManagementLabel ManagementLabel Creation/Modification/DeletionCreate and classify labels (e.g., personnel information, external sharing, etc.) as sub-items of the grade.Selectionlink
Security Classification Label ManagementLabel ManagementGrade Undetermined ManagementWhen a grade is deleted, the lower label moves to 'Grade Undetermined' and can be reassigned.Selectionlink
Log ManagementLog Integration QueryUser Log InquiryViewable user activity logs for all servicesEssentiallink
Log ManagementLog Integration QueryAdmin Log InquiryViewable admin activity logs for all services • Includes detailed information by event such as registration, modification, deletion (target of change, field name, etc.)Essentiallink
Log ManagementLog Integration QueryFilter SearchFiltering logs by period, user, department, and service is possible.Essentiallink
Security and Authentication SettingsAccount Security SettingsSetting Account Deactivation PeriodAutomatic account deactivation if not logged in for the set period • Deactivated accounts can be reactivated from the user management menuEssentiallink
Security and Authentication SettingsAccount Security SettingsUnused Account Automatic Deactivation PolicyAutomatically deactivate user accounts that have not logged in for more than the set period (default 90 days) • Exclude Admin accounts • Automatically record reasons for deactivation • Can be set with a toggle for usagespecializationlink
Security and Authentication SettingsAccount Security SettingsAutomatic Deactivation of Conditional Policies When Changing DepartmentsIf the user's department (group) changes and they leave the existing department, automatically deactivate the registered personal conditional policy. • If only a group is added (A→A,B), it is not considered a departure, so the policy is maintained. • Individual activation settings for each service are possible. • Operates the same way in all group change paths, including manual modifications and synchronization.specialization-
Security and Authentication SettingsAccount Security SettingsPassword Rule SettingsMinimum password length, character combination, and required character inclusion settings are possible • Excluded for users with external account integration such as Microsoft and SAMLEssentiallink
Security and Authentication SettingsAccount Security SettingsSetting Password Change FrequencyPassword Change Required Cycle Settings • Extension Count and Duration Settings AvailableEssentiallink
Security and Authentication SettingsAccount Security SettingsPassword Reuse RestrictionRecent password reuse prohibition setting available for N passwords (e.g., if set to 2, the last 2 cannot be reused)Essentiallink
Security and Authentication SettingsAccount Security SettingsAutomatic Logout SettingsAutomatic logout settings for inactivity timeout • Individual time settings available for each service (10 minutes, 30 minutes, 1 to 12 hours) • Applicable services: Management Center, SHIELD Drive, SHIELD GateEssentiallink
Security and Authentication SettingsAccount Security SettingsAutomatic Logout for Duplicate LoginAutomatic termination of existing sessions when a new connection occurs from a different IP with the same account • Individual settings with service-specific toggles • Applicable services: Management Center·SHIELD Drive·SHIELD Gatespecializationlink
Security and Authentication SettingsAccount Security SettingsRecent Access InformationIt is possible to set whether to display the last access date and time · IP upon login.Essentiallink
Security and Authentication SettingsAccount Security SettingsAccount Authentication Policy SettingsAccount temporary lock setting when the number of authentication failures exceeds • Number of failures: Select 5·10·15 times • Lock time: Select 5·10·30·60 minutes • Applies only to manual login users not using SSOEssentiallink
Security and Authentication SettingsAccount Security SettingsUser Initial Password SettingManual Registration (Individual · CSV Batch) Initial Password Rule Settings • Users need to change to a new password after the first login with the initial password.Essentiallink
Security and Authentication SettingsInbound ProvisioningMicrosoft 365 SynchronizationFull synchronization or specified AD group synchronization is available • Supported group types: Security groups · Mail groups • When synchronizing specified groups, unselected groups and members will be deleted • Manual enrollment administrators can also link MS accountsEssentiallink
Security and Authentication SettingsInbound ProvisioningSCI Server SynchronizationSCI server IP·Port integration settings available • Integration test button provided • Supports domain conversion settings if the ID is not in email formatSelectionlink
Security and Authentication SettingsInbound ProvisioningAutomatic synchronization cycle settingAutomatically synchronize at the set time every day • Can be activated or deactivated with a toggle switchEssentiallink
Security and Authentication SettingsInbound ProvisioningManual Synchronization수동 동기화- Execute immediate synchronization with a button - Display success/failure status and completion time after synchronization is complete - Prevent duplicate execution during synchronization in progressEssentiallink
Security and Authentication SettingsInbound ProvisioningPath Display Reference Group SettingsYou can check the user affiliation group path on the log page with the group setting • Microsoft Full Synchronization: The administrator directly sets one top-level root group • SCI Server: The top-level group is automatically set (no separate selection required)Selectionlink
Security and Authentication SettingsUser Authentication Method ManagementSecurity365 CertificationSecurity365 own ID·password authentication methodEssentiallink
Security and Authentication SettingsUser Authentication Method ManagementCSP Certification (Microsoft)Microsoft 365 Account Integration Login Support • When activated, on the login pageMicrosoft 로그인Button Display • Users linked with Microsoft Sync can log in with their MS accountEssentiallink
Security and Authentication SettingsUser Authentication Method ManagementCSP Certification (Google)Google account linked login support • When activated, on the login pageGoogle 로그인Button DisplaySelectionlink
Security and Authentication SettingsUser Authentication Method ManagementSSO Authentication (SAML)SAML-based IdP integration SSO authentication support • IdP configuration, SP configuration, Redirect URL configuration requiredEssentiallink
Security and Authentication SettingsLog SettingsBackup Cycle SettingsDaily, monthly, and yearly log backup cycle settings are possible.Essentiallink
Security and Authentication SettingsLog SettingsLog Collection Period SettingsSetting the log collection period to be included in the archive file • The collection period includes logs from the day before the backup date for the selected duration (e.g.: selecting 30 days, backup date 8/15 → logs from 7/16 to 8/14)Essentiallink
Security and Authentication SettingsLog SettingsArchive File ManagementSet maximum number of archive files to save • Automatically delete older files when exceeded • Direct download available from file listEssentiallink
Security and Authentication SettingsExternal Log TransmissionBackup log external transmissionAutomatic transfer of log backup files to an external server using SSH/SFTP • Configuration items: SSH ID·PW·IP·Port·Transfer destination path • Transfer is not possible if the path does not existSelectionlink
Security and Authentication SettingsExternal Log TransmissionConnection TestExternal server connection test feature provided • Save settings button activated after passing the connection testSelectionlink
Security and Authentication SettingsLog DeletionAutomatic Deletion of Log FilesAutomatic deletion setting for original logs after backup completion possible • Use: Delete backed-up original logs (irrecoverable) • Do not use: Retain original logsSelectionlink
Logo SettingsLogin Page SettingsLogo ChangeLogin page logo image upload/change available • Supported formats: PNG/SVG/JPG • Recommended size: Width 160~356px · Height 34px · Maximum 2MBSelectionlink
Logo SettingsLogin Page SettingsChange FaviconBrowser tab favicon changeable • Supported formats: ICO/PNG • Recommended size: 16×16 · 32×32 · Maximum 500KBSelectionlink
Logo SettingsLogin Page SettingsChange Tab NameChangeable browser tab title text • Allowed special characters: -, _, &Selectionlink
Logo SettingsLogin Page SettingsButton Hide SettingsLogin page button hiding possible • Password reset button hiding • Sign up button hiding (On-Premise only)Selectionlink
Logo SettingsService-specific logo settingsChange GNB LogoYou can change the logo in the top header of each service console • Supported formats: PNG/SVG/JPG • Recommended size: Width 140px · Height 30px · Maximum 2MBSelectionlink
Logo SettingsService-specific logo settingsFavicon/Tab Name by ServiceFavicon and browser tab name can be set individually for each service • Independent settings for admin page and user page respectivelySelectionlink
SettingsMenu Display ManagementDisplay Settings for Selection MenuHome Menu · Security Classification Label · Optionally set the visibility of the Conditional Policy menu to simplify the management screen • When 'Conditional Policy' is hidden, all users can access the service with just ID/PW.Selectionlink
SettingsApproval Service SettingsUse of Approval ServiceActivation/Deactivation Settings for the Approval Process of Integrated Services • If not used, the approval service-related menu will not be displayed on the user page.Selectionlink
System MonitoringSystem MonitoringViewing Resource Usage by NodeReal-time monitoring of CPU, memory, disk, and network usage**(On-Premise Only)**• Time series chart (up to 7 days) provided • Log view administrator role does not display menuSelectionlink
Service AccessUser Page Access ManagementProviding a user-specific pageSupport for users to navigate to the user page of the subscribed service after logging in.Selectionlink
Service AccessUser Page Access ManagementSeparation of Admin/User Page PortsSeparate the administrator page and user page to operate on different ports • Network access policies can be independently applied per page.Selection-