Session Lifetime Configuration
The Session Lifetime Configuration page lets users with the Organization Administrator user role adjust the duration and limits of user sessions on individual Portal instances to strengthen account security and maintain compliance. These settings can only be configured at the organization level.
Configuration optionsβ
Option | Option description |
---|---|
Session policy | Defines what happens with your session when you close your browser. This sets the rules for storing and deleting cookies, which directly impacts security. Available options:
|
Maximum session duration | A fixed value limiting how long a session remains valid, starting from login time. It does not take into regard the time passed since last activity unless the Session refresh setting is enabled. Available options:
|
Session refresh | Enabled by default. When enabled, the userβs session is extended for the Maximum session duration period whenever any activity (any click or interaction) is detected on the Portal instance. |
Session inactivity timeout | Disabled by default. When enabled, users will automatically be logged out after the specified period of inactivity. It overrides the Maximum session duration setting. Available options:
|
Non-persistent session limitations
Non-persistent sessions may not always work as intended due to browser behavior, such as:
- Session restore settings. Restoring a browser session can also restore the session cookie.
- Closing tabs instead of the browser. Cookies remain active until the session expires through inactivity timeout or maximum session duration.
In these cases, non-persistent sessions do not offer additional security.
Updating these settings does not log out users whose sessions remain valid. For example:
- users whose session has been active for 1 day are not logged out if the Maximum session duration has been updated from 7 days to 4 days
- users whose last activity was 1 hour ago are not logged out if the Session inactivity timeout has been updated from 1 hour to 2 hours
The settings are applied only after you click the Save button in the upper right corner of the screen.