# Locks

[In this section](https://my.tuna.am/team_bastion_certificates) you can create locks to quickly restrict user access to servers.

![admin_locks](/en/assets/images/admin_locks-656695338bc34e8ddbc10bcf29da849d.png)

If you want to deny access to a server and group of servers by label, login, or specific user.

## When is this needed?

Many examples can be imagined, here are some:

* You have a former employee who needs to have access to all infrastructure immediately revoked.
* You want to restrict access to production servers during the New Year holiday moratorium.
* Maintenance work on one server and you need to close access to it for all users.

## Example

You cannot add a lock without any conditions, you need to fill in at least one condition:

* Server
* Role
* User
* Login

In this example, user *Zhenya* will be prohibited from logging into any servers, and all current sessions will be immediately closed.

![admin_lock_add](/en/assets/images/admin_lock_add-c5240e11102893ce4e5b3d035ba4b57c.png)

tip

This section is available to the **Founder**, **Owners** and **Administrators**.
