Limit concurrent user logins

Hi all,
One of our customers is trying to limit the number of concurrent user logins to 1.
He has deployed a 2500 WLC (v7.4) with a Dot1x SSID. Authentication against external radius server (IAS).
Configured the following:
Max Concurrent Logins for a user name: 1
But doesn't work despite of the value configured in "Max-Login Ignore Identity Response" option (enable|disable).
My doubt here is if that these parameters just work when we are using local authentication or if it could be a bug with this particular software train.
I've found contradictory info regarding this particular topic.
Thanks in advance.
Best regards,
Alberto

Hi Saurav,
Thanks for the info provided.
Our problem here is that despite the value of max-login-ignore-identity-response (enable|disable) we always can establish multiple simultaneous connections with the same username credentials. 
Does Max Concurrent Logins for a user name work with external radius authentication? Are we missing something else?
Thanks in advance.
Best regards,
Alberto

Similar Messages

  • Concurrent user logins using same user ID- Is it Possible?

    Hi Experts,
    I want to know how can I make the configuration for user ID in SAP to login in to the system at once through different machings. Basically concurrent user logins using same user ID.
    Is this is possible?  whats the configuaration? Am I violating any SAP license policies?
    Please help me with this.

    just for the knowledge, it is possible and via following parameter
    login/disable_multi_gui_login
    http://help.sap.com/saphelp_nw04s/helpdata/en/22/41c43ac23cef2fe10000000a114084/content.htm
    However, it is not permitted to use in Production at all. But sometimes, only in critical situations, for eg. we have only a few basis IDs and some maintenance task is to be carried out involving more resources, multiple gui login can be utilized in sandbox to for that ID.
    But, it is for sure that, USMM report will be sent to SAP for the sandbox too. So client is subjectable. If you, as a basis guy, are going to try it, then please do it only after the confirmation from the client and only if client needs it.

  • EP Performance Tunning and concurrent user login problems

    Hi all.
    We have a EP , integrated with Windows AD and SAP R3.
    In real situation, there will be 1000 users login in EP in 0.5 hours. And their operation time will be 6-8 hours, connect to R3 or other applications.
    Is EP can support such concurrent user login scenario ?
    if EP fails, is there some performance monitor tool or performance tunning issue ?

    Hi
    EP supports this logon load, however it all depends on sizing and architecture!  Also the content of the STARTPAGE can be critical (make it "light").
    If the portal fails, then often it is only one J2EE server process, which fails - so by having more server-processes will be an easy/minimum form of high availability.  A "real" HA solution must be considered if your business will not work without the portal og SAPGUI connections can be used as workaround/fallback in such situations.
    BR
    Tom Bo

  • Limit Concurrent Users

    Hello,
    Is there a way on EP6 to limit concurrent user sessions.  For example, user "JoeSmith" is not able to logon to more than 2 session of the Portal.
    We are running EP6 Patch4.
    thanks,
    Harman

    Interesting thought. I guess if there is way, it has to be thru the authentication module. So IMO write a new JAAS module for authentication and before you authenticate the user, apply your criterion and if successful log the user in.
    This is would be all custom code. I don't think there is a out of the box way available.
    Pankaj

  • How do we find out how many concurrent users login at peak time?

    Hi Frienz
    PLease let me know if there is any database trigger that we can keep to monitor this?
    Poonam Sachdeva

    You can also use audit features of the database to audit user connections/disconnections
    and write the query to get what you need.
    Or you can also use with 9i/10g a LOGON/LOGOFF trigger to audit session connection and disconnection in a audit table and then write the query on this audit table to analyze the maximum number of connections.

  • Limit a Windows 7 machine to 1 user login at a time

    I've searched everywhere for a solution to this but have not found anything outside of restarting the machine.
    I need to limit a Windows 7 computer to only allow one user logged in at a time. This machine has applications only allow one user to run them at a time. So if a user locks this machine and walks off and if the next user switches user and logs in, none of
    the programs will work because the first user's session is now suspended.
    Is there anything that will kick the suspended user off? So if a user forgets to log out and the screen is locked, the second user's login would force the first user to log off?

    I know this was 1.5 year ago, but people search the web for these solutions for years and for years these solutions continue to help others, but not when people are so very much OFF TRACK with what the OP asked for. It shouldn't surprise me, but it is astounding
    at how people do not communicate well and instead of reading what the OP asked for carefully the proposed answer here does NOT address the OP's question... it got the "BREEZE BY ANSWER".
    NOW - TO the OP Cherickson HERE's the BEST answer I've been able to determine on my OWN since ALLLLLLLLL of the other posts online I read ALSO were answered OFF TOPIC:
    DISABLE FAST USER SWITCHING (speaking from a Windows 7 environment)
    Here's the GPO to do it (Open Group Policy Management Editor on a DOMAIN or Active Directory server):
    Default Domain Policy [ServerNameHere] > Computer Configuration > Administrative Templates > System > Logon > Hide entry points for Fast User Switching
    Set Hide entry points for Fast User Switching to Enabled.
    FOR non-DOMAIN non-Group-Policy controlled PC's use "Local Group Policy Editor" via gpedit.msc
    (NOT NOT NOT "Local Security Policy" via secpol.msc) and visit:
    Local Computer Policy > Computer Configuration > Administrative Templates > System > Logon > Hide entry points for Fast User Switching
    Set Hide entry points for Fast User Switching to Enabled.
    Now, to be "EXACTING" here, this does not "PREVENT" multiple users from logging into the same PC at one time "per say", but it ends up having that effect on "PEOPLE" because "PEOPLE" are very predictable
    in a network environment and they aren't worried about saving PC resources for themselves or others... they just use the PC.
    Setting Hide entry points for Fast User Switching to Enabled REMOVES the option for users to "SWITCH USER" while they are logged into Windows (fat client) and it also removes the "SWITCH USER" from the Welcome/Logon screen,
    thereby forcing them to "LOG OFF" themselves (or whomever is logged in) manually and thereby then they are presented with an option to Log In using their own Windows user account. This is great, because it keeps the PC resources for just 1 logged
    in user at a time instead of you being called to examine a slow PC only to find that the lazy users out there left 2 or 3 or MORE users logged in at once despite being told 100 times or more that they shouldn't do that. :) EXPERIENCE??? :)
    Now, if you have an advanced user, doing things with other users logging in the background of their own user session (IE: RUN-AS on some shortcut lets say) then they should still be able to do all that jazz too even though Fast User Switching is turned off.....
    but this is usually pretty unlikely and usually that would be someone amongst the IT staff.
    So to summarize:
    Set policy "Hide entry points for Fast User Switching" to Enabled in order to have only 1 user logged on any given PC "at one time" - IE: Prevent concurrent Windows user Logins
    NOW.... I elect MYSELF and MY ANSWER as BEST ANSWER in this THREAD, because its the ONLY ANSWER that addresses the OP's request.

  • Limit concurrent logins on a WS 2008 environment

    Hi all
    I'd like to ask if there is any way you can limit concurrent logons on a WS2008 AD domain.
    Thing is i want my users (1500+) to only be able to log in on one machine at a time.
    I saw a program called LimitLogon.exe but i'm not going to use that because it is unsupported, it requires IIS, it's quite old and it requires a OU structure in AD. I also saw a program called UserLock but we cannot afford that here since we would have to
    buy too many licenses.
    I was also wondering why this feature isn't in server 2008? It's a quite common problem in many different branches in which IT has been applied (my case, a hospital).
    Any help on this?
    (I don't mean concurrent logins on remote, i mean just be able to log onto one machine with their account at a time)
    Thanks in advance.
    Alex

    Hi Alex,
    As far as I know, there is no build-in feature to limit number of logins of users from many machines in Active Directory Domain. Microsoft has released the LimitLogin
    tool. The tool stores logged-on information in a custom AD partition via a Microsoft IIS hosted Web service, a client component, and a logon and logoff script. To run the tool, IIS must be installed along with ASP.NET.
    For more information on the tool, please refer to the following link:
    Limit Login Attempts With LimitLogin
    http://technet.microsoft.com/en-gb/magazine/2005.05.utilityspotlight.aspx
    If you do not want to run the tool, there is also ways to only allow users to log into certain machines which can help limit where they are logged into as a workaround.
    For example:
    1. Go to AD Users and Computers, find the user who you want to restrict, right click and choose Properties, click the Account tab, choose “Log On To”.
    Select “This user can log on to:” “The following computers”, then add the computers as you want.
    2. Use group policy to restrict some domain users to log on certain computers
    Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
    Deny logon locally
    If you consider using LimitLogin, you can refer to the following links on how to install and use the tool:
    http://sgwindowsgroup.org/forums/t/586.aspx
    http://rahuldpatel.wordpress.com/2009/08/03/limitlogin-step-by-step/
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    Thanks.
    Nina
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Limit the number of concurrent users

    Is it possible to limit the number of concurrent users for the application in Websphere or at the http management level?

    You don't say what version of Websphere you are using, but here's how you might limit the number of sessions in Websphere 4.0 Advanced Edition (other versions may differ):
    Open the Administrative Console. Go down the tree to Nodes, Application Servers and click on the server you want to control (likely Default Server). In the right panel, click on the Services tab. In that panel, click on the Session Manager Service and click the Properties button. That pops up a new dialog.
    Select the Advanced tab here. Put a number in the Maximum in-memory Session Count field and uncheck the Allow Overflow checkbox. Click OK, etc, etc, and you'll probably have to restart Websphere.
    I said "might" because I don't know if this will do what you want or not. Read the help file associated with that dialog and judge for yourself.

  • Limit user login in multiple RODC

    I have 2 RODC and a RWDC.i prepopulate some password on RODC1 And Some on RODC2 cache database. i already read this article http://www.frickelsoft.net/blog/?p=232
    I want to limit user login in multiple RODC.(for example user1 can not login to os in different RODC).
    So i want to know is there is a way to limit user to login just from its RODC cache database not RWDC active directory?(i want user in RODC1 cant not login to RODC2.How can i do this?)

    Hi,
    Do you want to restrict users from logging into a client computer that belongs to another site? Or do you want the users to get authenticated only to the RODC's where their credentials cached? 
    If you configured your sites and services properly the clients will choose the DC belongs to their own site and subnet. DC locator is the service name which is responsible for assigning a logon DC to the client.If the DC's are in different sites you
    can configure the sites and services to point the client to correct DC in a site. AD authentication always distributed based on the sites and services you configured.
    You can configure ldapsrv records to authenticate against specific DC.
    RODCs do not register Domain Name System (DNS) general records (records that are associated with the domain itself and not with a specific site), as read/write domain controllers (RWDCs) do. This is the default behavior of RODCs. Although you can tune an
    RODC to register DNS general records, we recommend that you not change the default behavior.
    The main impact of RODCs not registering DNS general records is that a client computer cannot find an RODC in its site without reaching an RWDC (that is, a domain controller that registers the general records) if the client computer does not have a record
    for the name of the site where the client computer is placed.
    Source: Placing Several RODCs in the Same Site
    http://technet.microsoft.com/en-us/library/ee522995(WS.10).aspx
    Domain Controller Locator : an overview
    http://blogs.technet.com/b/arnaud_jumelet/archive/2010/07/05/domain-controller-locator-an-overview.aspx
    LdapSrvWeight & LdapSrvPriority
    http://blogs.dirteam.com/blogs/carlos/archive/2006/05/10/How-to-lessen-your-PDC_1920_s-load.aspx 
    http://technet.microsoft.com/en-us/library/cc816793%28WS.10%29.aspx 
    Regards,
    Rafic
    If you found this post helpful, please give it a "Helpful" vote.
    If it answered your question, remember to mark it as an "Answer".
    This posting is provided "AS IS" with no warranties and confers no rights! Always test ANY suggestion in a test environment before implementing!

  • Maximum Number of Concurrent User Sessions Limit?

    Please can you tell me if there is a limit for the maximum number of concurrent users sessions that can access the Portal? If so, where is the setting and how do I change it?
    By the way, I am not experiencing any issues; I am asking purely for information purposes
    Thanks.

    There used to be under one of the services in service configuration.  I thought it was under portal runtime, but I can´t see it now.  It mentioned it in the TZTEP1 course, but I haven´t got it with me.
    Having said that, I don´t know if it worked!
    Paul

  • ESS/MSS limit of concurrent users

    Hi,
    I have to implemantation the ESS/MSS in sap with SOA. I would like to know : How many users will be accessing ESS at the same time? In particular, how many should be the concurrent users ( to do the same activity ) will be accessing ESS , to ensure the  server response doesn't deteriorate? ( Side web frontend )
    Thanks a lot,
    Silvia Sacchi

    hi.
    i tried to draw a picture with a typical ess scenario. from the browser to the abap backend.
    it's not too sharp but i think you will see what i mean.
    [ESS Scenario|http://picasaweb.google.at/lh/photo/bHbfx56fo1y3mfo6w2e_Tw?feat=directlink]
    You see that you need lots of infrastructure. All parts need - more or less - resources. If there is heavy load you need more cpu and ram (for example adding more server processes on the as java of the portal) but you also have to configure the web dispatchers, the as java, the as abap (icm). Thats the architecture for the ess service. It doesn't help when asking "how many people can call a time sheet on abap". you have to look at all components...
    If i were you and i do not know lots about the load i would start conventional (not completely oversized). It's a process to get a well performing system. You always have to make corrections when running productive. thats the job we love :o)))
    regards, martin

  • Prevent the same user login on multiple computers at the same time

    prevent the same user login on multiple computers at the same time

    Is there any way (currently running 2012 Servers) that we can prevent users from logging into multiple domain computers simultaneously with the same username?
    We still want them to log into those computers, just not simultaneously?
    LimitLogin utility not work in Windows 2012 server.
    Thanks.
    Babu
    Unfortunately Windows has never offered this feature as a built-in feature, but there are several possibilities discussed in these articles:
    https://social.technet.microsoft.com/Forums/windowsserver/en-US/0103b5e7-0db5-4fb4-bfe7-d7132983880a/limit-concurrent-logins-on-a-ws-2008-environment
    http://www.edugeek.net/forums/windows-server-2008-r2/61216-multiple-logins.html
    http://windowsitpro.com/windows/prevent-multiple-logons-gpos
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • 802.1X wirelss restriction on User Login policies

    Hi all,
    Seeking some technical idea on Wireless 802.1x setup.
    Business requirement is:
    "User login policy: to limit the number of concurrent login by a single user only apply to one device at any given time. "
    There is no problem on PEAP/MSCHAPv2 login, only thing is the same user credential able to be use and login on multiple device, in the same time.
    On the NAD part, we configure these on WLC but still cannot achieve our objective
    - advanced eap max-login-ignore-identity-response disable
    - netuser maxuserLogin 1
    Seeking technical solution on this case, please advice. Is there anything need to tweak on the directory server or ACS part?
    The components using as below:
    Supplicant 1: Window 7, authentication method using PEAP/MSCHAPv2
    Supplicant 2: iPhone iOS version 6.x
    Authenticator: Cisco Wireless Controller 5800 Series on code version 7.2
    Authentication server: Cisco secure server ACS 5.3.0.40
    Identity Source : Microsoft server 2008 R2 ADDS, single forest single domain.
    attached the network diagram: topo1.png

    http://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/112175-acs51-peap-deployment-00.html

  • Is there a way to create user logins or some other way to ...

    Is there a way to create user logins or some other grouping for a set of applications to use (memory) resources optimally -- for example only mail and Safari and Word in one grouping and another for Safari and an audio recording application, etc.?

    It is possible to use Parenal Controls to limit which applications can be used be a particular user account.
    But it's not really necessary as far as managing memory.
    Matt

  • Load testing with concurrent users on HTTP Web

    Hello,
    I am trying to do load testing my PHP Web Application.
    I record (with Firefox) and developed the testing script with OpenScript,
    but I found that I could only test with "Iteration" feature.
    Is there any way to do load testing with concurrent users ( multi users login at the same time ) which defined in databank?
    Thanks for help.

    Hi
    You need to load the script into OLT (Oracle Load Testing) you can download it from here you need the first link Oracle Application Testing Suite and run the OATSxxx.exe to install OLT.
    Regards
    Alex

Maybe you are looking for

  • Photoshop elements 8 for Mac - how to move photos (events) from iphoto to pse

    I have figured out how to move one  photo over through opening a file.  But I can't move a full event or album from iphoto.  Ive tried going to bridge but when i click on the iphoto folder, it takes me into my iphoto and I'm not sure what do then, no

  • How can I see what has been purchased on my iTunes account

    How can I see what has been purchased on my iTunes account and when?

  • Zen micro, how do i delete everythi

    i want to delete all the tracks i put on it and start from scratch.is there a way to do this without going one by one? i tried deleting the playlist, deleting the genre (only had one on there so far) but the music is still there when i go to "all tra

  • Unable to mount MDM Console

    Hi, I am new to SAP MDM. I was just trying to mont the console(MDM_TestConsole) and was trying to start it by right clicking and start MDM Server. The system prompts me with this message below. *Error Starting: MDMTestConsole(MDM Server): The machine

  • Problems after trying to restore my ipod touch

    i bought my ipod touch from my brother and when i tried to restore the ipod to the factory settings the screen froze and now its froze on the apple logo screen with a line across the top and itunes will not recognize it plz help