Multiple Logon in Production

All,
I am trying to understand the actual risk of allowing users multiple logon in production systems. As of now I believe that should logon credentials be stolen then it's not possible to monitor illegal logons and also a possible data inconsistency.
Please throw some light, have tried searching with the logon profile parameters in the forum and online, but nothing concrete found.
Kind Regards,
AJS

Hi Avinash,
Production system should not allow multiple logon.
Please have a look at below for restrict multiple logins :-
[Restrict multiple logins for a single user in Portal |/message/6942923#6942923 [original link is broken];
[Limiting Number of Users Logged On |http://wiki.sdn.sap.com/wiki/display/EP/LimitingNumberofUsersLogged+On]
Hope it helps
Regards

Similar Messages

  • Multiplie logon message *every* time I try to logon?

    Hello,
    I hope that someone can help me with this: before few weeks I had sudden failure in SAP and I was disconnected from the system and after that momment *every* time I logon I see this multiplie logon message:
    http://img255.imageshack.us/img255/7163/04feb1310713pm.jpg
    Why is this happening exactly and how can I solve it? I must note that *only* I use this licence and know the password and nobody else didn't for sure.
    Many thanks in advance for prompt replies!
    Cheers,
    Sam

    Hi Sam,
    The old session is stuckup.You can either:
    1. Goto SM04 and try to kill the session by either logging off user system wide else goto Session -> Select Session -> End session.
    2. If this doesnt work , you can goto OS level and Kill the Process by kill -9 <pid> . Pls confrim with the administrators before doing this.
    3.Else even if this doesnt work, you have to reboot the server. Pls be careful if it is a production system.
    Pls try and let us know.
    Regards,
    Madhura.

  • SAPGui for Windows Multiple Logon with Portal

    Hi,
    We are using SAPGUI for Windows in Portal in the external window, we are also using it the SAPConsole form the desktop. While using from desktop, the multiple logon (within same client) complains / comes with the pop-up with two standard options.
    We would like achieve the same functionality of popup (Restricting multiple logons for the same client) within the portal, any ideas?
    I came across certain threads and also notes but none seem to provide a solution....
    [Restrict multi logon to R/3 system from portal using single sign on.    |Restrict multi logon to  R/3 system from portal using sigle sign on.;
    [SAP GUI 7.10 and SSO - multiple logons issue. How to restrict it?    |/thread/1623980 [original link is broken];
    Note 142724 - Prevention of multiple SAPGUI logons
    Thank you in advance.
    Best regards,
    Dharmi
    Edited by: Dharmi Tanna on Jun 25, 2010 2:09 PM

    Lonny,
    The best way to authenticate users when they logon using SAP GUI for Windows, is to use SNC authentication in SAP GUi. Then, the browser iview will launch the GUI and the GUI will authenticate the user using their AD credentials issued during the Windows logon. You will need to setup an SNC library on both the ABAP system which the user is logged onto, and the workstation where SAP GUI is installed.
    If you don't use SNC, and you just launch SAP GUI for Windows from browser, then an SSO2 ticket is used to authenticate the user to the ABAP stack, and this is not secure due to the fact that the SAP GUI session which is used to pass the SSO2 ticket is not protected - anybody can intercept the SAP GUI session, take the SSO2 ticket from this traffic and logon as that user - clearly this is bad security and needs SNC to make it secure.
    Thanks,
    Tim

  • Remote Desktop Gateway and WebAccess Deployment - Multiple Logon Prompts

    I'm having a few issues with some multiple logon prompts using "Connect to a remote PC" via RD Web Access.
    I am able to log onto the RDWeb without a problem.
    Essentially once I make a connection to my end-device I first receive a logon prompt, I'm authenticated, then I'm asked again for another logon prompt. Any ideas how to resolve this?
    My layout is simple:
    1 VM in the DMZ that has the Remote Desktop Gateway and Remote Desktop Web Access roles installed. No connection broker, or session host.
    With my deployment I have a wildcard certificate bound to the Remote Desktop Gateway and it is bound properly in IIS. Remote Desktop functionality through the RDGateway works just fine. However, the only nuisance is that I get prompted multiple times for
    credentials when accessing the end-device regardless if my connection is from a domain-joined machine or a non-domain joined machine.
    I've tried using Web Single Sign On via http://anandthearchitect.com/2014/01/20/rds-2012-r2single-sign-on-using-windows-authentication-for-rdweb-page/ and it still does not work.
    Any ideas?
    Thanks,
    Dan

    Hi Dan,
    How many prompts are you seeing?  Expected behavior for Connect to a remote PC would be this:
    1. Log on to RDWeb
    2. Select Connect to a remote PC tab
    3. Enter server name in Connect to box, click Connect
    4. Unknown publisher warning, click Connect
    5. Credentials prompt, it should say These credentials will be used to connect to the following computers: 1. rdgw.domain.com (RD Gateway server) 2. remote.domain.com (remote computer)
    6. After entering credentials and clicking OK it should log you in to the remote computer.  This assumes that the destination is authenticated properly (usually via certificate) and the credentials are valid for both the RDG and the remote
    computer.  Normally in a domain environment the same credentials (domain\username) would be valid for the RDG and the remote server.
    -TP

  • How to make "check for multiple logons" mandatory in webdynpro application.

    Hi SDN members,
    Im having a problem with an application developed in webdynpro abap.
    We require that  end-user only have a session per computer (ip address),
    I already tried to achieve this by configuring the webdynpro application throguh SICF and going to Error Pages -> Logon Errors --> System Logon and mark the checkbox Check for multiple logons.
    This configurations give only a warning when the user logs multiple times, and show a checkbox letting the user decide to end or not the previous sessions.
    How to make end previuos sessions mandatory ??
    Regards,
    Franklin Cedillo

    You would have to enforce this at the application level. You can get the IP address of the current client from the framework - IF_WD_APPLICATION method GET_REMOTE_ADDRESS.
    You could write an entry with the IP address into a temporary table during WDDOINIT.  You could clear the entry in the WDDOEXIT.  Also during the WDDOINIT, check to see if there is already an entry for this IP address.  If so, then fire an exit nagivation plug to a static MIME object or BSP page that explains why the user can only be logged in once.

  • Multiple logon screen doesnt appear and session end in 30mins

    Hi all,
    I have a problem with my login session.
    Multiple users use the same SAP USER ID to logon. but when i try to logon ( even when others are logged on d same id) i dont get the option for multiple logon screen to terminate/continue without ending the other logons but i get to logon directly without this screen as if i am the only user of this id.
    but when others try to logon (when others are logged on the same id) they get the screen of multiple logon with options.
    and my session termiates after every 30mins but their sessions continue without any termination. please note that no one termites the session by themselves.
    I am not able to figure out what is happening. I changed my pc, my gui, updated to the latest patches, changed the lan ports but nothing changes. i continue to face the same problem. please provide d needful solution.
    thanks.

    Check these parameters
    login/disable_multi_gui_login
    Controls the deactivation of multiple dialog logons
    Available as of SAP Basis 4.6
    login/multi_login_users
    List of excepted users, that is, the users that are permitted to log on to the system more than once.
    Available as of SAP Basis 4.6
    Find the full list of relevant parameters at:
    http://help.sap.com/saphelp_nw04/helpdata/en/22/41c43ac23cef2fe10000000a114084/content.htm

  • Multiple logon for Microsoft Server 2008 R2

    I currently work for the U.S. Government as a System Administrator.  I'm in the middle of an inspection on my system and one of the inspector asked me about multiple logon for Microsoft Server 2008 R2.
    How many times are you allowed to logon to Microsoft Server 2008 R2 before it lock the system?  And also if I'm the system administrator what is the limit on logging to different systems with my account.
    These are questions that I do not have an answer to and I couldn't find any assistance on the Tech Support website.
    Thank you for your assistance.
    Andre'

    Hi,
    If you mean how many users can log on the same computer, this is limited by the resource:
    If You  refer system administrator as domain administrator, domain administrators have full administration rights to their domain.
    Alex Zhao
    TechNet Community Support

  • Multiple Logon disable

    Dear All ,
    while multiple logon are performed.SAP pop-up a message with 3 options
    1.terminate logon
    2.continue with the logon
    3.continue with the logon terminating other sessions.
    Here we Want to disable the 2 option that is : continue with the logon.
    Here we  came to know : we can add the following parameterto the instance profile
    logon/disable_multi_gui_login
    Pl guide with the steps how to add this & where ( Tcode & procedure ) .
    Regards

    Hi,
    Please go through the below SAPnote to get better clarity on it.....
    Note 142724 - Prevention of multiple SAPGUI logons
    PS: If this parameter is set to value 1, multiple SAPGUI logons (in the same client and with the same user) are blocked by the system. The parameter is effective during the SAPGUI logon. Logons to the system using the Internet Transaction Server (ITS) or Remote Function Call (RFC) are not influenced by the profile parameter. Furthermore, SAPGUI transaction calls (iViews) that are placed through the Workplace or the Enterprise Portal are not controlled with regard to multiple logons...
    Regards,
    PY

  • How to block the multiple logons with NWBC?

    Hello,
    With Sapgui we have the possibility to prevent the multiple dialog logon by profile parameters (login/disable_multi_gui_login).
    How to prevent the multiple dialog logon using NWBC to the same system?
    Best regards
    Frédéric Blaise
    e-Kenz S.A.
    Luxembourg

    Hello,
    I opened a ticket at Sap but unfortunately they do not have a solution even if the problem is known.
    "Unfortunately, due the HTTP protocol nature, is not possible to force a single logon via web browser. The profile parameter login/disable_multi_gui_login is solely valid for SAPGUI logons."
    "Since this case is known since the Web Application Server was created, I am pretty convinced that SAP knows about the fact that multiple logons cannot be blocked (you can only give a warning for the user)."
    Since we monitor multiple connections with the SM04 transaction and notify customers that they may be controlled by Sap.
    Best regards
    Frédéric

  • How to edit "license information for multiple logon" screen

    hey gurus
    i need to know how to edit or modify the 'license information for multiple logon" screen. this screen usually pops up when a user tries for a multiple logon to sap. We have activated the parameter 'login/disable_multi_gui_login' but we would like to modify the screen in such a way that only one radio button which says 'terminate this logon' should exist. we would prefer to remove the option of 'continue with this option and end any other logon'. Now i searched but i could not find anything to implement this so i am here and i need your advice and suggestions.
    thanks in advance.
    cheers.
    nate

    hey bernhard
    many thanks for your reply..i appreciate your help. its just that its not explicitly mentioned we cant modify the screen in the note.
    Is there any other note that specifically say so?
    thanks for your time buddy.
    regards

  • Disable the multiple Logons in ECC6 and allowing few users

    Dear All,
    I need to disable the multiple Logons in ECC6 and allowing few users, can multilogin in system.
    I have seen that the parameter login/disable_multi_gui_login and login/multi_login_users can be set.
    But need to know did any once use in Ecc6 system and what values to be given in login/multi_login_users.
    Please suggest .
    Regards,
    Kumar

    I have found an exmaple on the web of using javascript (it opens a child window that polls the parent window, and invalidates the session if the parent window is closed). I agree there always appears to be loop holes around most of th e solutions i've come across.
    I had the same idea about invalidating any previously known session for the same userid, I'm pretty new to the java/web app world so I'm struggling with finding the information I need. I couldn't find any methods to call to invalidate another session, I only came accross example where the current session invalidated its own session via call to the session object, do you have any idea how I would do that for other sessions.
    Mant thanks for your input.
    Derek.

  • Multiple logons in R/3

    Hi,
    I have many roles with transactions iviews. User has tendancy to open portal in new window/tab for accessing multiple tranactions at the same time. Opening portal in new window/tab creates new logon in R/3.
    Can we change configuration so that opening more portal sessions in new tabs/new windows will be registered as multiple sessions in R/3 and not multiple logons?
    Thanks,
    Apurva

    Hi
    Please Check these threads
    1.[Multiple Logon|Multiple Logon;
    2.[Restricting the multiple logons in portal|Restricting the multiple logons in portal;
    3.[how to prevent multiple logon|how to prevent multiple logon;
    Hope it help you.
    Best Regards
    Satish Kumar

  • Does XI Adapter (ABAP Proxy)  allows multiple LogOn Languages??

    Hi ALL,
      I have a doubt like whther we can give multiple logon languages in the XI Receiver Adapter ( ABAP Proxy ).
    For example,
      I am getting data in "English" - EN  , "Russian" - RU , "Japanese" - JA etc. Can I give these all languages as "LogOn Language" while configuring the XI receiver adapter? If so how? else, is there any other option for this.
    Thanks,
    Anudeep.

    hi,
    I don't think it's possible to precise dynamically the logon lanaguage which has to be used in the receiver XI adapter (proxy).
    [Help SAP on XI adapter|http://help.sap.com/saphelp_nw70/helpdata/EN/99/115281baba404890d2561617a78409/frameset.htm]
    Maybe a solution could be in the mapping to have a rule which determines the receiver (EN, RU,JA) that should receive a message or another one, and then for each receiver to specific a unique CC. So in your case to define three CC (one for each langauge): EN + RU + JA.
    Anyway I don't really understand the reason to manage that... The interest of logon language is when we want to write a text. But in SAP you can write a Japan text even if you are log-in in English by specifying the Language Code !
    So maybe the solution of your problem, is to send to your proxy the text but also the ISO language code linked to this text, so to do what SAP does in IDoc and BAPI.
    regards
    Mickael

  • How to suppress License Information for multiple logon screen?

    Hi,
    While LOGIN we will get "License Information for multiple logon screen" will displayed.
    How to suppress that screen.
    Regards,
    Bala

    >
    bala virupaksha wrote:
    > Hi,
    >
    > While LOGIN we will get "License Information for multiple logon screen" will displayed.
    > How to suppress that screen.
    >
    > Regards,
    > Bala
    and why would you want to do that?
    does your contract with SAP say, that you may use multiple logins for free? would SAP's contract-issue department agree that -in your case- it's not necessary to record multiple logins?
    have you read this part of the SAP license policy?
    SAP gives express notice that the accessing of a system by more
    than one person using one and the same named user constitutes
    a breach.
    tell me this does not apply to you ...

  • WebSapconsole multiple logon

    Hi... How do we do to work in our RF devices with multiple logon with the same user ID??
    We've already checked the option "Permit multiple logon" in SAPConsole Administrator, but the system just show us the message: "User XXX already logged on to client ###".
    TIA.
    A.

    Have you already found a solution for this issue, because I have the same problem!
    I think it isn't possible or it should be avoided! The following is a quote from SAP Note 380399: "According to the connection rules for RF transactions, a user must not be connected to the same system simultaneously from a few RF devices."
    Thanks in advance!
    SJ

Maybe you are looking for

  • Cannot change "New Event" to an event name in iCal

    For several days whenever I enter a new event in iCal I can put in all the information (times, etc.), but it will not allow me to change "New Event" that appears at the top to the name of the event.  So I have several events now called "New Event," a

  • Skype /callto: doesn't work with federated Lync Us...

    Skype (removed for privacy) is a Lync federated user. If I call to this user "(removed for privacy) from Skype Client directly, then it works fine....

  • Duplicate pages in script printing

    The requirement is to print purchase order. I have output type created using tcode NACE.One Zform is assigned to the output type created in NACE. I need to make changes in Zform in such a way that same pages should be printed again. How can I achieve

  • How do i get new bios?

    How do i install a new bios. Cant it be done from windows , the msi liveupdate thingy? or do i have to flash with disk or something , plz explain to me how to do!

  • Flash Player 10.1 Plugin : volume control using plugin params?

    I have a situation where I need to play third-party SWF files that are not authored by me.  Some of these files contain sound, and some of them are network enabled.   I need to be able to mute these as the audio is terribly annoying. Is there a way t