<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow a single user logon for each session via GUI/SSH in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/597327#M118806</link>
    <description>&lt;P&gt;We had max session count set to 3. FIPS standard is 4.&amp;nbsp;&lt;BR /&gt;We have 2 administrators and we constantly lock ourselves out of the PA when we are more actively engaged.&amp;nbsp;&lt;BR /&gt;Session Count default is 0(Unlimited) and Session Time default is 0 which translate to 30 days.&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 16:17:08 GMT</pubDate>
    <dc:creator>J.Kim530884</dc:creator>
    <dc:date>2024-09-09T16:17:08Z</dc:date>
    <item>
      <title>Allow a single user logon for each session via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548782#M112023</link>
      <description>&lt;P&gt;hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to check when each admin account logs into its own session via GUI and SSH.&lt;BR /&gt;If either one login to a 2nd session then it will be denied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it achievable? I can't find any article from Palo Alto regards to this.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 14:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548782#M112023</guid>
      <dc:creator>Kevin_Ncs</dc:creator>
      <dc:date>2023-07-10T14:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a single user logon for each session via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548786#M112024</link>
      <description>&lt;P&gt;No, admins are allowed to log in multiple times&lt;/P&gt;
&lt;P&gt;you can limit their idle timeout in "device &amp;gt; setup &amp;gt; management &amp;gt; authentication settings" if you're worried they have too many 'sleeping' sessions open&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:14:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548786#M112024</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-07-10T15:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a single user logon for each session via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548787#M112025</link>
      <description>&lt;P&gt;Does this article works?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEhWCAU&amp;amp;lang=en_US%E2%80%A9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000kEhWCAU&amp;amp;lang=en_US%E2%80%A9&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548787#M112025</guid>
      <dc:creator>Kevin_Ncs</dc:creator>
      <dc:date>2023-07-10T15:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a single user logon for each session via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548923#M112040</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300749"&gt;@Kevin_Ncs&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The option works perfectly fine, however I'd really caution thinking through setting this value to 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Admin sessions are tracked whenever they access the GUI/CLI/API; so say that you have an admin who is making a change in the GUI and loses access to the device due to the change, if restricted to a single session they've now effectively locked out of the device. You'll be waiting for the established session to be removed prior to it allowing access via another session.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 13:11:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/548923#M112040</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-07-11T13:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Allow a single user logon for each session via GUI/SSH</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/597327#M118806</link>
      <description>&lt;P&gt;We had max session count set to 3. FIPS standard is 4.&amp;nbsp;&lt;BR /&gt;We have 2 administrators and we constantly lock ourselves out of the PA when we are more actively engaged.&amp;nbsp;&lt;BR /&gt;Session Count default is 0(Unlimited) and Session Time default is 0 which translate to 30 days.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 16:17:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-a-single-user-logon-for-each-session-via-gui-ssh/m-p/597327#M118806</guid>
      <dc:creator>J.Kim530884</dc:creator>
      <dc:date>2024-09-09T16:17:08Z</dc:date>
    </item>
  </channel>
</rss>

