Hello, Luiz!
First of all, it seems that this problem should be solved nevertheless organizationally. For example, add information to the main page (welcome page or something else) about personal responsibility for unauthorized entry under the credentials of another user or about possible sudden checks of the IBM and existing fines in accordance with the license agreement.
If we talk about the technical side, the problem is that you can't disconnect a specific ID (you can see all IDs in TM1Top), as far as I know, you can only disconnect all user connection IDs at once ("Server manager" -> "Disconnect Clients" or through TM1 REST API).
Therefore, the most appropriate way seems to be that the user, before entering the authorization page in PAW, first goes to a special site that has fields for entering a login and password and verifies the client name and, for example, current computer account and does not allow to go further in PAW, if the credentials are different. If everything is successful, then sends it to PAW.
This site can use TM1 REST API to connect to the TM1 model and search in the attributes or configuration cube for the client and the account of each user machine.
Another option, for example, is to configure Integrated Login, SSO, so there is no need to enter credentials.
--
Best regards,
Dmitry
------------------------------
Dmitry Noskov
Intapplex
------------------------------