<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Tips &amp;amp; Tricks: Allow a Single User Logon For Each Session Via GUI/SSH in General Articles</title>
    <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-allow-a-single-user-logon-for-each-session-via/ta-p/549221</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548782" target="_blank" rel="noopener"&gt;Allow a single user logon for each session via GUI/SSH&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;" by&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300749"&gt;@Kevin_Ncs&lt;/a&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt; and responded to by&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; .&lt;SPAN&gt; Read on to see the discussion and solution&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I want to check when each admin account logs into its own session via GUI and SSH.&lt;BR /&gt;If either one login to a 2nd session then it will be denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it achievable? I can't find any article from Palo Alto regards to this.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By default, admins are allowed to log in multiple times. If you're worried they have too many 'sleeping' sessions open you can limit their idle timeout in "device &amp;gt; setup &amp;gt; management &amp;gt; authentication settings"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Referring to this article it is absolutely feasible:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEhWCAU&amp;amp;lang=en_US%E2%80%A9" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEhWCAU&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditorkiwi_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditorkiwi_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="rtaImage.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/51553i084C8F6927393187/image-size/medium?v=v2&amp;amp;px=400" role="button" title="rtaImage.jpeg" alt="rtaImage.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;CLI:&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@FW# set deviceconfig setting management admin-session max-session-count
  &amp;lt;value&amp;gt;  &amp;lt;0-4&amp;gt; Set the maximum number of sessions administrators are allowed&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However I'd really caution thinking through setting this value to 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Admin sessions are tracked whenever they access the GUI/CLI/API; so say that you have an admin who is making a change in the GUI and loses access to the device due to the change, if restricted to a single session they've now effectively locked out of the device. You'll need to wait for the established session to be removed prior to being allowed access via another session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Fri, 14 Jul 2023 01:12:09 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2023-07-14T01:12:09Z</dc:date>
    <item>
      <title>Tips &amp; Tricks: Allow a Single User Logon For Each Session Via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-allow-a-single-user-logon-for-each-session-via/ta-p/549221</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This Nominated Discussion Article is based on the post "&lt;/SPAN&gt;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548782" target="_blank" rel="noopener"&gt;Allow a single user logon for each session via GUI/SSH&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 01:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-articles/tips-amp-tricks-allow-a-single-user-logon-for-each-session-via/ta-p/549221</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2023-07-14T01:12:09Z</dc:date>
    </item>
  </channel>
</rss>

