Click here to get back home

Permit only one network logon per user

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Permit only one network logon per user Christian Thies [Ar] 08-15-2007
Get Chitika Premium
Posted by Christian Thies [Ar] on August 17, 2007, 10:43 am
Please log in for more thread options
Steve, you're absolutely right about the risks.

But let me explain a little dipper my situation, my apologies to all for not
doing this from the beginning



I'm building an application that encodes data in an audio stream encoded
with windows media. At the other side, I have developed a decoder, where the
data is decoded. The stream is decoded with windows media.



I'm selling this stream.



The way that this stream is accessed is providing a valid username and
password.

I assign a unique username and password per user of this service.



So, I need to keep an eye in possible steals or not allowed shares of
usernames and passwords. Because of this, I need to make sure that, at
least, no one can log in two or more times simultaneously



Regards, and thanks for your help



Christian


> If you don't mind, I'd like to use your situation here to chat a moment
> about risk. Limiting simultaneous logons is usually considered for these
> reasons:
>
> 1. Alice logs on at workstation A. Alice then logs on at workstation B,
> which sits next to workstation A.
>
> 2. Alice logs on at workstation A. Alice then logs on at workstation B,
> which is in another room. Bob wanders along, sees that someone is logged
> into unoccupied workstation A, and messes around.
>
> 3. Alice logs on at workstation A. Alice shares her ID/password with Bob.
> Bob logs on at workstation B.
>
>
> #1 is not a security risk. #2 and #3 are security risks. Trying to
> prohibit simultaneous logons isn't very practical because there are
> circumstances in which the tracking mechanism might get out of sync.
> Better mitigations are to teach people to log off when not using a
> workstation and not to share IDs/passwords with others--and to back up
> these policies with consequences.
>
> Also, realize that tools like CConnect apply to the user's entire domain
> access, not just to your application. That is, CConnect doesn't have a way
> of preventing Alice from logging on multiple times only for the use of
> your application--it applies to her domain account on the whole.
>
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>> I'm building a product that is accessed with a username and password, and
>> for preventing unauthorized access to it, I need to prevent multiple
>> simultaneous logons with the same username and password
>>
>>
>>
>> Sorry about my English. Let me know if the answer is clear
>>
>>
>>
>> Christian
>>
>>> Why do you need to do this? What security risk do you need to mitigate?
>>>
>>> Steve Riley
>>> steve.riley@microsoft.com
>>> http://blogs.technet.com/steriley
>>>
>>>
>>>> Hi, I have Windows 2003 domain working. I need to allow only one
>>>> network logon per user.
>>>>
>>>>
>>>>
>>>> The example is:
>>>>
>>>>
>>>>
>>>> User: username
>>>>
>>>> Status: Logged
>>>>
>>>>
>>>>
>>>> If user username try to login from a different machine, and he is
>>>> logged in another, the login attempt must be denied
>>>>
>>>>
>>>>
>>>> How can I accomplish this?
>>>>
>>>>
>>>>
>>>> Thanks in advance
>>>>
>>>>
>>>>
>>>>
>>
>>



Similar ThreadsPosted
"the local policy of this system does not permit you to logon interactively" April 11, 2007, 5:15 pm
Fatal exception 0E has occurred at 0028:c000A97F in VXD VMM(01)+000997F Seems to be after network logon. May 30, 2007, 12:54 pm
User Logon April 15, 2008, 9:54 pm
user logon time tracking November 3, 2006, 1:08 am
User must change the password at first logon November 5, 2008, 11:19 am
Questions on Authenticated Users and Access This Computer From Network User Right July 2, 2006, 8:38 pm
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. April 12, 2007, 6:03 pm
"Network Service" account is UNABLE to write to a network shared folder April 18, 2007, 7:01 pm
Workstations showing logon failures by users can still logon? November 27, 2007, 6:56 pm
Just one logon January 5, 2006, 11:56 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap