Skip to content

Limit the number of concurrent user sessions #18162

@elasticmachine

Description

@elasticmachine

Problem statement: Allow admins to define a maximum number of concurrent sessions per Kibana user. This builds on top of previous work, that introduced server side sessions .

Detailed approach: [This document|https://docs.google.com/document/d/1TpgCdz-S687s2XjTyTuJDx7Ig-rju_nnXfiefyt3dok/edit?usp=sharing], For [the MVP|https://docs.google.com/document/d/1TpgCdz-S687s2XjTyTuJDx7Ig-rju_nnXfiefyt3dok/edit#bookmark=id.ditlr5w78trc] see final section.

Justification: Example customer Enhancement Requests:

  • [14109|https://github.com/elastic/enhancements/issues/14109]
  • [13049|https://github.com/elastic/enhancements/issues/13049]
  • [12108|https://github.com/elastic/enhancements/issues/12108]
  • [8393|https://github.com/elastic/enhancements/issues/8393]
  • [3676|https://github.com/elastic/enhancements/issues/3676]
  • [997|https://github.com/elastic/enhancements/issues/997] etc..

In addition NIST compliance ([800-53 AC-10|https://csrc.nist.gov/Projects/risk-management/sp800-53-controls/release-search#/control?version=5.1&number=AC-10])

Release: The MVP is aimed for 8.7

Metadata

Metadata

Assignees

Labels

Feature:Security/AuthenticationPlatform Security - AuthenticationTeam:SecurityPlatform Security: Auth, Users, Roles, Spaces, Audit Logging, etc t//enhancementNew value added to drive a business result

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions