my environment: winflector server version 3.9.4.0a in a windows 10 pro machine, no active directory, but authentication mode is windows authentication with only users who are members of the local "Winflector users" group receiving authorization to connect after providing correct user name and password.
i had initially assumed that when users connect via winflector client gui, the domain name field needs to be filled up correctly. indeed, if that field is incorrectly filled, the user will get a "not authorized" error message. but it turns out a user can connect without filling in the domain name field as long as the user fills in user name and password correctly. is this the expected behavior? is it possible to make filling the domain name field a required input -- that way, an outsider needs to guess 3 fields (user name, password, domain name) correctly instead of just the user name and password?
now that winflector server's winflector authentication can additionally use mac address filtering for authentication, does this make the winflector authentication mode more secure than windows authentication mode with or without the use of active directory?
thanks for any help!

