Symantec Privileged Access Management

 View Only

  • 1.  Query for login session

    Posted Oct 26, 2022 04:35 AM
    Hi Experts,

    Is there a way in PAM tools to prevent or restrict any concurrent login from the same account to multiple device?

    Regards,
    Atifah


  • 2.  RE: Query for login session

    Broadcom Employee
    Posted Oct 26, 2022 08:52 PM
    Hi Atifah, I don't quite understand what you are after. Are you asking about restricting the number of logons to PAM by the same PAM user? Or are you concerned with a user opening multiple access sessions to different target devices in general? Or is it a question if you can restrict use of a target account for only one target device at a time? In all cases the answer would be that PAM does not have a configuration for such limitations, but it would be helpful to understand your question better, and the motivation for raising it here.


  • 3.  RE: Query for login session

    Posted Oct 27, 2022 02:59 AM
    Hi Ralf,

    My apologies for not being clear. Your first assumption was correct. Is there any way to restrict a PAM account from log in to multiple workstation.
    For example, user A access to PAM on machine A and cannot use the same access to log in to PAM on another machine.

    Thank you for your advice.

    Regards,
    Atifah


  • 4.  RE: Query for login session

    Broadcom Employee
    Posted Oct 27, 2022 02:20 PM
    Hi Atifah, PAM doesn't block multiple user logons. What is your concern here?


  • 5.  RE: Query for login session

    Posted Oct 27, 2022 10:10 PM
    Hi Ralf,

    The objective is to prevent account sharing across multiple workstations. Is there any way to restrict to only one login session at a time?

    Thank you,
    Atifah


  • 6.  RE: Query for login session

    Broadcom Employee
    Posted Oct 27, 2022 10:48 PM
    No. The only restrictions you can impose is limit from where the user can login by defining allowed IP ranges. Access times can be limited as well. If users share their logon credentials, that would be a problem whether or not multiple sessions are allowed. Feel free to raise an idea for an enhancement on the ideation page (Ideas link in the top menu of this community site).


  • 7.  RE: Query for login session

    Posted Oct 28, 2022 01:07 AM
    Thank you, Ralf for your advice!


  • 8.  RE: Query for login session

    Broadcom Employee
    Posted Nov 10, 2022 01:45 AM
    Hello Atifah, I forgot to mention the "Concurrent Remote Connections Allowed" setting on the Configuration > Security > Access page, see documentation page Server Access Options Configuration. This option does allow you to restrict user access to PAM to one source IP at a time. It works only per node in a cluster, not cluster-wide, but may be of use to you.