---
title: Multiple User Selection in SSH Proxy
slug: kronpam-reference-guide-3-5-0/multiple-user-selection-in-ssh-proxy
description: Learn how to enable and configure the multi-account selection feature for seamless connection to target systems. This document presents user scenarios and the corresponding behavior, accompanied by helpful screenshots of the SSH Proxy terminal's multiple-
docTags: 
createdAt: 2022-07-27T12:26:46.000Z
---

This feature allows the user to select the appropriate account to connect to the target system, as there could be more than one option. This feature is enabled by configuring the possibility of more than one connection. Possible choices are **Manual Login**, **Global User**, **SAPM User**, and **Assigned Credential User**. To add “Session User (LDAP User)” to this list, the “addSessionUserToUserSelection” property needs to be configured.

1. Navigate to **Devices**> **Device Groups**.
2. Click th&#x65;**&#x20;Edit&#x20;**&#x74;he **Next** buttons.
3. Expand the **Additional Credentials** section.
4. Toggle on the **Add Session User to Credential Selection**.

The table below shows which user has priority, and the resulting Kron PAM behavior:

| **Add Session User to Credential Selection** | **Add Manual Login To Credential Selection** | **Global User Count** | **Behavior**                                                                                  |
| -------------------------------------------- | -------------------------------------------- | --------------------- | --------------------------------------------------------------------------------------------- |
| False                                        | True                                         | 0                     | Ask for username/password                                                                     |
| False                                        | True                                         | 1                     | List the **Manual**<br />**Login** and **Global User** options.                               |
| False                                        | True                                         | More than 1           | List the **Manual**<br />**Login** an&#x64;**&#x20;Global User** options.                     |
| True                                         | False                                        | 0                     | Connect with **Session User&#x20;**&#x61;utomatically.                                        |
| True                                         | False                                        | 1                     | List the **Session User&#x20;**&#x61;nd **Global User** options.                              |
| True                                         | False                                        | More than 1           | List the **Session User&#x20;**&#x61;nd **Global User** options.                              |
| True                                         | True                                         | 0                     | List the **Session User** and **Manual Login** options.                                       |
| True                                         | True                                         | 1                     | List the **Session**<br />**User**, **Manual Login**, and **Global User&#x20;**&#x6F;ptions.  |
| True                                         | True                                         | More than 1           | List the **Session User**, **Manual Login**, an&#x64;**&#x20;Global User&#x20;**&#x6F;ptions. |

The table above reflects the possible scenarios that can be defined with the properties listed (**Add Session User To Credential Selection** and **Add Manual Login To Credential Selection**) and the behavior that occurs for the related scenarios. The Global User count for each scenario is shown under the ‘Global User Count’ column.
For instance, if a global username and Session User (LDAP/AD User) property is set at the same time, it results in the scenario shown in this figure:

::Image[&#xD;&#xA;]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/MuXfbtlNvqZf1AJnIYry6_image.png" size="68" width="804" height="1076" position="center" caption="Global Username/Password and Session User Properties set at the same time" showCaption="true"}

On the SSH Proxy terminal, the user will have a multiple-user selection window available and will be eligible to select one of the connection ways to access the target device.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/LuTfNXsw-KZF01ViShbw8_image.png "Multiple User Selection on SSH Proxy Terminal")

