STIGUI
V-284541CAT II — Medium severitySV-284541r1244953_rule

The Ivanti Policy Secure must limit the number of concurrent sessions to one for each administrator account/or administrator type.

Rule version IVPS-NM-000062 · STIG v1 · 2026-07-09

Discussion

Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator based on account type, role, or access type is helpful in limiting risks related to denial-of-service (DoS) attacks.

This requirement addresses concurrent sessions for administrative accounts and does not address concurrent sessions by a single administrator via multiple administrative accounts. The maximum number of concurrent sessions should be defined based upon mission needs and the operational environment for each system. At a minimum, limits must be set for SSH, HTTPS, account of last resort, and root account sessions.

Check

1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Realms. 2. Click the configured admin realm being used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Limits".

If the "Maximum number of sessions per user" field shows any value other than "1", this is a finding.

Fix

1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Realms. 2. Click the configured admin realm being used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Limits". 4. In "Maximum number of sessions per user", enter "1". 5. Click "Save Changes".

Identifiers

Group ID
V-284541
Group title
SRG-APP-000001-NDM-000200
Rule ID
SV-284541r1244953_rule
Check ID
C-89106r1244254_chk
Fix ID
F-89011r1244255_fix