Rule version AWTM-NM-000039 · STIG v1 · 2026-09-14
Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator based on account type, role, or access type is helpful in limiting risks related to denial-of-service (DoS) attacks.
This requirement addresses concurrent sessions for administrative accounts and does not address concurrent sessions by a single administrator via multiple administrative accounts. The maximum number of concurrent sessions must be defined based upon mission needs and the operational environment for each system. At a minimum, limits must be set for SSH, HTTPS, account of last resort, and root account sessions.
1. Log in to the WTM Web UI. 2. Navigate to Admin >> User Management >> Login Control.
If the "User Session Limit" is not set to "8" or to the organization's acceptable user session limit, this is a finding.
1. Log in to the WTM Web UI. 2. Navigate to Admin >> User Management >> Login Control. 3. Click "Enable". 4. Set the "User Session Limit" to "8", or the organization's acceptable user session limit. 5. Click "Commit".