How to make the session policy stricter?

Written by Анатолій
Updated 4 days ago
  1. Save the session during idle time. This option is responsible for the time during which the session is active in idle mode. To make it more restrictive, set the ‘session-hours’ value to a value lower than that in the configuration

  2. One session per user. An option that allows or disallows one session for one browser

  3. One session per user per IP. A parameter that allows or disallows one session per IP address

  4. Maximum number of login attempts before locking. A parameter that determines the number of attempts to enter an incorrect password before locking. To make it more stringent, set the value of ‘max-login-attempts’ to a value lower than in the configuration

  5. Lockout time after several login attempts. The parameter that is responsible for the period for which the user will be blocked. To do this, set the ‘max-attempts-timeout-minutes’ value to a value greater than that in the configuration

  6. The list of allowed IP addresses. List of IP addresses from which users can access the platform

  7. List of blocked IP addresses. List of IP addresses from which users cannot access the platform.

Did this answer your question?