Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fullmoon
Contributor III

AD SSO multiple login

hi experts, is there a way I can limit the number of log-in if the network is part of AD SSO? What I mean is how do I block multi log-in using single account?

Fortigate Newbie

Fortigate Newbie
3 REPLIES 3
Rick_H
New Contributor III

I' m not sure this can be done in FSSO. You can only do this indirectly in Active Directory itself by modifying the " Log On To..." list on the Account tab of an AD user' s account. That doesn' t limit the number of simultaneous logons, though. It limits the devices from which a user can authenticate. There may be a way to further restrict in Group Policy, but I' ve never researched it.
svacs
New Contributor

You need to enable the admin-concurrent option in the CLI. e.g. config system global set admin-concurrent enable end I' m not sure when this feature was implemented though. You can find more information about it in the FortiOS Handbook - Authentication for FortiOS 5.0 under " Restricting number of concurrent user logons" .
victorhud

#config system global #set admin-concurrent enable/disable #set policy-auth-concurrent enable/disable #end with these comands can limit concurrent auth in global mode(applied to all users) Does any know if is it possible to block the concurrent-auth by user or group with LDAP?
Labels
Top Kudoed Authors