ACR Rules

  1. Home
  2. Docs
  3. ACR Rules
  4. Security (28)
  5. Users should be signed in with a maximum of one session

Users should be signed in with a maximum of one session

Introduced in version 1.12 (12 August 2020)

Users should only be able to be signed in through one client, like a desktop browser or a tablet, so that every sign in is unique and can be traced to its corresponding user.

Non-compliant example:

If multiple sessions per user is enabled, users can be signed in on different clients, like a desktop browser and a tablet. However, this might encourage account sharing and/or exploitation.

Mendix 8 Project Runtime Settings

Compliant example:

Mendix 8 Project Runtime Settings

In Project Runtime Settings set Multiple sessions per user on No.