Security Best Practices
6 min read
Updated Sep 23, 2026
Introduction
This guide provides security best practices for deploying and using GuacamoleID. Following these recommendations helps ensure maximum protection for your devices and sensitive data.
Authentication Security
Face Profile Best Practices
Creating Strong Profiles
- Good Lighting: Register profiles in well-lit conditions
- Multiple Angles: Look slightly left, right, up, down during registration
- Consistent Expression: Use a neutral expression
- Remove Obstructions: Take off sunglasses, move hair from face
Profile Management
- Multiple Profiles: Create profiles for different lighting conditions
- Regular Updates: Re-register if appearance changes significantly
- IR When Available: IR profiles are more secure and reliable
- Limit Profile Count: Only create necessary profiles
Profile Security
- Don't Share Profiles: Each user should have their own profiles
- Protect Registration: Register in private, secure locations
- Review Periodically: Audit profile list for unauthorized additions
- Secure Backup: If using cloud sync, ensure account security
Anti-Spoofing Configuration
Recommended Settings by Environment
| Environment |
Minimum Level |
Recommended Level |
| Home/Personal |
Passive |
Passive |
| Office |
Passive |
Active |
| High Security |
Active |
Depth Vision |
| Financial/Healthcare |
Depth Vision |
Depth Vision |
Anti-Spoofing Guidelines
- Never Disable: Always have at least Passive enabled
- Use Depth When Available: IR cameras provide best protection
- Test Periodically: Verify anti-spoofing is working
- Monitor Logs: Watch for spoofing attempts
Block Screen Security
Configuration Recommendations
Blocking Speed
| Risk Level |
Recommended Speed |
| Low Risk |
Medium |
| Standard |
Fast |
| High Risk |
Very Fast |
Block Screen Options
- Key Press to Windows Lock: Always enabled
- Camera Preview: Consider disabling in high-security environments
- Registration Button: Disable in high-security deployments
- Custom Background: Avoid showing sensitive information
Physical Security Integration
- Screen Position: Face away from windows and common areas
- Privacy Filters: Use physical privacy screen filters
- Camera Coverage: Ensure camera sees anyone approaching
- Clean Desk Policy: Lock screen when leaving
Device Security
Device Configuration
- Full Disk Encryption: Enable BitLocker or equivalent
- BIOS Password: Prevent unauthorized boot changes
- Secure Boot: Enable secure boot in BIOS
- Firmware Updates: Keep BIOS/UEFI current
Software Security
- Windows Updates: Enable automatic updates
- Antivirus: Use enterprise-grade protection
- Firewall: Enable Windows Firewall or better
- Application Updates: Keep GuacamoleID updated
Network Security
- VPN: Use VPN on untrusted networks
- WiFi Security: Only connect to secure networks
- Network Monitoring: Enable network protection features
- Remote Access: Secure any remote access methods
Account Security
Web Portal Security
- Strong Password: Use complex, unique password
- Two-Factor Authentication: Enable 2FA if available
- Session Management: Log out when finished
- Secure Access: Only access from trusted devices
Password Guidelines
| Requirement |
Minimum |
Recommended |
| Length |
8 characters |
12+ characters |
| Complexity |
Mixed case + numbers |
Mixed case + numbers + symbols |
| Uniqueness |
Unique to GuacamoleID |
Unique + password manager |
| Change Frequency |
Annually |
Every 6 months |
Account Recovery
- Recovery Email: Keep recovery email secure and current
- Security Questions: Use strong, non-guessable answers
- Backup Codes: Store recovery codes securely
- Contact Info: Keep phone/email updated
Organizational Security
Deployment Security
- Secure Distribution: Use signed installers
- Configuration Management: Deploy with secure defaults
- License Security: Protect license keys
- Enrollment Process: Secure device enrollment
Policy Recommendations
Mandatory Policies
| Policy |
Recommended Setting |
| Anti-Spoofing |
At least Passive |
| Block Screen |
Enabled |
| Auto-Lock |
5 minutes maximum |
| Password Fallback |
Enabled |
Role-Based Access
- Least Privilege: Grant minimum necessary access
- Regular Review: Audit permissions quarterly
- Separation of Duties: Distribute admin responsibilities
- Access Logging: Enable comprehensive logging
User Training
Essential training topics:
- How face recognition works
- Importance of anti-spoofing
- Recognizing security threats
- Reporting security incidents
- Privacy and compliance
Data Protection
Biometric Data Security
- Encryption: Biometric data is encrypted at rest
- Local Processing: Recognition happens on-device
- Minimal Storage: Only necessary data retained
- Secure Transmission: Encrypted cloud sync
Privacy Considerations
- Inform Users: Explain what data is collected
- Consent: Obtain proper consent for biometrics
- Data Retention: Follow retention policies
- Data Deletion: Honor deletion requests
Compliance
Regulatory Frameworks
GuacamoleID can help with compliance for:
- HIPAA: Healthcare data protection
- PCI-DSS: Payment card security
- SOC 2: Security controls
- GDPR: Data protection (EU)
- CCPA: Consumer privacy (California)
- BIPA: Biometric information (Illinois)
Documentation Requirements
Maintain documentation of:
- Security policies and configurations
- User consent records
- Access logs and audit trails
- Incident response procedures
- Training completion records
Incident Response
Preparing for Incidents
- Define Procedures: Document response steps
- Assign Roles: Identify response team
- Communication Plan: Know who to notify
- Testing: Practice incident response
Responding to Security Events
Unauthorized Access Attempt
- Review authentication logs
- Identify the source/method
- Strengthen affected controls
- Document the incident
- Report per policy
Spoofing Attack Detected
- Increase anti-spoofing level
- Review affected profiles
- Check for successful bypasses
- Investigate attack source
- Update security measures
Lost or Stolen Device
- Remote lock/wipe if possible
- Disable device in portal
- Revoke associated sessions
- Change related passwords
- Monitor for unauthorized access
Post-Incident Actions
- Root Cause Analysis: Understand what happened
- Remediation: Fix vulnerabilities
- Documentation: Record the incident
- Communication: Notify stakeholders
- Prevention: Implement improvements
Monitoring and Auditing
What to Monitor
| Category |
Metrics |
| Authentication |
Success/failure rates, patterns |
| Anti-Spoofing |
Spoofing attempts, blocks |
| Access |
Who accessed what, when |
| Compliance |
Policy violations |
Log Retention
| Log Type |
Minimum Retention |
Recommended |
| Authentication |
90 days |
1 year |
| Security Events |
1 year |
2 years |
| Admin Actions |
1 year |
3 years |
| Compliance |
Per regulation |
Per regulation |
Regular Audits
Monthly Reviews
- Review failed authentication attempts
- Check for unusual patterns
- Verify security settings
- Update as needed
Quarterly Reviews
- Full security configuration audit
- User access review
- Policy compliance check
- Training status update
Annual Reviews
- Comprehensive security assessment
- Policy updates
- Risk assessment
- Vendor security review
Security Checklist
Initial Deployment
- [ ] Install latest version
- [ ] Enable anti-spoofing (Passive minimum)
- [ ] Configure block screen settings
- [ ] Set appropriate auto-lock timeout
- [ ] Enable Windows password fallback
- [ ] Create face profiles in good conditions
- [ ] Verify all features working
Regular Maintenance
- [ ] Check for software updates
- [ ] Review authentication logs
- [ ] Audit user access
- [ ] Verify backup/recovery works
- [ ] Test anti-spoofing effectiveness
- [ ] Update profiles if appearance changed
High-Security Environments
- [ ] Enable Depth Vision anti-spoofing
- [ ] Set Very Fast blocking speed
- [ ] Disable block screen registration
- [ ] Enable comprehensive logging
- [ ] Implement network segmentation
- [ ] Regular penetration testing
- [ ] Continuous monitoring
Additional Resources
Security Documentation
- NIST Cybersecurity Framework
- CIS Controls
- ISO 27001 Standards
- Industry-specific guidelines
Training Resources
- GuacamoleID security training
- Security awareness programs
- Phishing simulation
- Incident response drills
- Security issues: security@guacamole.ai
- General support: support@guacamole.ai
- Documentation: docs.guacamole.ai