Identity & sessions
- TOTP multi-factor authentication
- Single-use recovery codes
- Session inventory and revocation
- Login history and rate boundaries
EzeAD combines user-facing protection with server-side boundaries, strict privileged execution, diagnostics and recoverable change workflows.
EzeAD separates the panel runtime from a narrow privileged execution path. Helpers validate operation, identity and path scope before server changes are accepted.

No single control carries the entire security story.
| Layer | Purpose | EzeAD controls |
|---|---|---|
| Prevent | Reduce unsafe states | Input validation, tenant scopes, MFA, HTTPS, safe defaults |
| Detect | Find drift and threats | Panel Doctor, service checks, malware scans, login history |
| Contain | Limit blast radius | Account isolation, scoped helpers, quarantine, feature lists |
| Recover | Restore a known state | Backups, versioned releases, snapshots, validation and rollback |

Rather than exposing raw scanner or firewall output as the product, EzeAD presents clear state, guided actions and protected evidence.
Review the technical model