Configure Windows authentication first
- In Windows Settings, open Personalization → Lock screen → Screen saver.
- Choose a saver and a Wait interval.
- Select On resume, display logon screen and apply the change.
Microsoft documents this option as the way to require sign-in when resuming from a screensaver. See Microsoft's screen saver instructions. Test the actual idle transition on your PC; a visual saver preview alone is not proof of the authentication behavior you need.
Add DeskLatch's separate rules
- Open Windows locked and enable Monitor while Windows is locked.
- For a simple setup, choose Restart for USB device connected and Do nothing for the other locked rows.
- Click Save. Keep DeskLatch running in your signed-in session.
The locked profile applies whenever Windows is confirmed locked, even with a grey tray icon. It does not require normal monitoring to be enabled. After you sign in, it waits for the next lock. A locked-row Do nothing also suppresses an armed normal rule for that same event.
What the screensaver setting adds
Auto-enable → Enable whenever a screensaver starts separately arms the normal Triggers profile when a saver is observed. Enable it only if you also want that behavior. It does not configure Windows authentication, and normal keyboard hooks do not provide secure-desktop coverage.
Check it without restarting
For a locked-only configuration, exit DeskLatch and launch its whole-app Test monitoring.cmd session before testing a saver and harmless USB device. Review simulated events after signing in. Return to a normal launch only after reviewing the rules. See safe testing and event history or the visible-desktop alternative.