Should the user always use a specific device? Then you can save the username in the endpoint and evaluate the attribute Authorization:[Endpoints Repository]:Unique-Device-Count. This approach is easier, but it doesn't work if the end devices use private MAC addresses.
An alternative approach is to use the Active Sessions Counter from the [Insight Repository] Authentication Source. This allows you to ensure that the user only goes online from one device at a time. Carson describes this approach in his posts.
------------------------------
Regards,
Waldemar
ACCX # 1377, ACEP, ACX - Network Security
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Mar 02, 2026 05:08 PM
From: amr.ragab@linux-plus.com
Subject: Prevent Users to Access many devices
I have a good knowledge of how configure services, policies, and profiles.
The customer wants to limit the number of devices a single user can use on the wireless network.
I know that if we need to control the device limitition we need an onboard license, and we now only have Access.
Original Message:
Sent: Mar 02, 2026 11:13 AM
From: chulcher
Subject: Prevent Users to Access many devices
How conversant with ClearPass are you?
You'd need to configure a concurrent device limit check in ClearPass.
------------------------------
Carson Hulcher, ACEX#110
Original Message:
Sent: Mar 02, 2026 10:55 AM
From: amr.ragab@linux-plus.com
Subject: Prevent Users to Access many devices
Hi Herman, thank you for your response.
I meant that the customer wants the end user, when connecting to the wireless, just use 1 device with their credentials and cannot connect from other devices, and every user in the network is allowed to connect through 1 device (mobile/tablet/ wireless laptop), no more.
We integrate with Aruba Central as we configured SSIDs and services on CPPM for Wireless.