Message Text For Users Attempting To Log On is a policy that displays custom text to users at sign in. Administrators use it to communicate alerts, instructions, or operational notices directly on the authentication screen, before access is granted to the device or session.
What Message Text For Users Attempting To Log On Does
Message text for users attempting to log on is a sign-in policy that presents an administrator-defined notice before access is granted. It gives organisations a controlled way to communicate security, legal, or operational information at the authentication boundary.
Why It Exists in the Authentication Flow
This message appears at the point where a user is trying to establish a session, so it reaches people before the system completes sign in. That makes it useful for change windows, support contact details, acceptable-use reminders, maintenance notices, or sensitive-environment warnings.
Because the text is shown before access is allowed, it can influence user behaviour without depending on email, chat, or separate broadcast channels. It is also a policy control, not a decorative banner, so the wording should be deliberate, approved, and kept consistent with the environment it protects.
How Administrators Use It
Administrators typically use this setting to present a short, clear message that users must see during logon. The content should be concise enough to read quickly and specific enough to support the intended operational purpose, such as a legal notice, incident advisory, or support instruction.
The most effective messages are stable, readable, and appropriate for all users who may encounter the sign-in screen. If the environment serves multiple populations or device types, the message should still be understandable in that first-contact context and should not rely on prior knowledge.
Security and Governance Value
A pre-logon message can reinforce awareness at a sensitive control point, but it is not an access control by itself. It does not verify identity, limit privilege, or stop misuse; it simply communicates information before authentication completes. In practice, its value comes from setting expectations at the exact moment a user is about to enter a protected system.
Used well, it can reduce confusion during maintenance, support incident response communications, or support policy acknowledgement patterns. Used poorly, it becomes ignored background text, so it works best when the wording is intentional and the message is reserved for information that genuinely matters to users at sign-in.
Risk and Threat Considerations
Misuse of logon messages can create false confidence, poor usability, or information leakage. If administrators place sensitive operational details, internal contact paths, or environment-specific clues in the banner, they may give unnecessary context to anyone who can reach the authentication screen.
Failure mechanism: The message is visible before access is granted, so an overly detailed or outdated notice can disclose operational information or train users to ignore warnings that should be meaningful.
Impact: The organisation can weaken the value of the control, expose internal details to unauthorised viewers, or reduce attention to legitimate sign-in notices during an actual security or maintenance event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-8 — System Use Notification | Defines pre-login warning banners shown before access is granted |
| Recommendation — Use AC-8 to present an approved system-use notice before logon completes. | ||
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | Pre-authentication notices sit at the access boundary and support controlled access |
| Recommendation — Align the sign-in notice with PR.AA-01 boundary controls and approved access messaging. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access-control policy can include logon-screen notices and user awareness at entry points |
| Recommendation — Document the logon message under access-control policy and keep it approved and current. | ||
| CIS Controls v8 | CIS-5 — Account Management | Login banners are part of controlled account access and user-facing access messaging |
| Recommendation — Include sign-in banners in account-access governance and review them with access policy changes. | ||
Practitioner Guidance
What to watch for: Keep the message short, accurate, and purpose-built for the sign-in moment. Treat it as a controlled communication channel, and avoid turning it into a long policy dump, an informal support note, or a place to publish sensitive internal information.
Governance implication: The banner should have an owner, an approval process, and a review cadence so the wording stays current and consistent with security, legal, and operations requirements. A stale message is often worse than no message at all because it creates noise at a critical access point.
Related resources from NHI Mgmt Group
- What should users do when a text message appears to come from a public authority during a crisis?
- How should teams migrate active sessions without forcing users to log in again?
- What breaks when passwords are shared informally by text message or email?
- What breaks when non-administrator users are allowed to log on to domain controllers?