Plan requirement
| Subscription | Any plan |
| Access | Admin |
How long somebody stays signed in. A balance between an unattended laptop and agents who sign in six times a day and start leaving the tab open.
Set it
- Open the security settings in Admin Center.
- Set the session length for team members.
- Set it separately for end users.
- Tell agents before it changes.
What it protects against
An unattended machine, a shared workstation, a laptop left in a meeting room. The session ending limits how long that exposure lasts.
It does nothing about a stolen password, which is what two-factor is for.
Match it to how people work
Agents in an office on their own machines can have longer sessions. Shared workstations, or people working in public spaces, warrant shorter ones.
Where the work varies, set it for the riskiest case rather than the most convenient.
Too short costs more than it looks
An agent signing in six times a day loses time and starts leaving the tab open deliberately, which is the behaviour you were trying to prevent.
Security controls that irritate people get worked around.
Customers should be longer
Somebody checking their ticket a week later should not have to sign in again if you can avoid it. The risk is lower and the friction costs you contact.
Single sign-on may govern it
Where staff sign in through your identity provider, its session policy often applies. Check which setting actually decides before adjusting this one.
Say why when you shorten it
People accept a change they understand. An unexplained shorter session reads as a fault, and you will hear about it as one.
Comments
0 comments
Article is closed for comments.