Setting session timeouts

Plan requirement

Subscription Any plan
Access Admin

How long somebody stays signed in. A balance between an unattended laptop and agents who sign in six times a day and start leaving the tab open.

Set it

  1. Open the security settings in Admin Center.
  2. Set the session length for team members.
  3. Set it separately for end users.
  4. Tell agents before it changes.

What it protects against

An unattended machine, a shared workstation, a laptop left in a meeting room. The session ending limits how long that exposure lasts.

It does nothing about a stolen password, which is what two-factor is for.

Match it to how people work

Agents in an office on their own machines can have longer sessions. Shared workstations, or people working in public spaces, warrant shorter ones.

Where the work varies, set it for the riskiest case rather than the most convenient.

Too short costs more than it looks

An agent signing in six times a day loses time and starts leaving the tab open deliberately, which is the behaviour you were trying to prevent.

Security controls that irritate people get worked around.

Customers should be longer

Somebody checking their ticket a week later should not have to sign in again if you can avoid it. The risk is lower and the friction costs you contact.

Single sign-on may govern it

Where staff sign in through your identity provider, its session policy often applies. Check which setting actually decides before adjusting this one.

Say why when you shorten it

People accept a change they understand. An unexplained shorter session reads as a fault, and you will hear about it as one.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.