Skip to content
  • There are no suggestions because the search field is empty.

SSO Session Timeout Configuration and Guidelines

Overview

The SSO (Single Sign-On) session timeout settings are security controls designed to protect confidential company and employee information by automatically ending inactive sessions. These settings help prevent unauthorized access, especially when a user’s workstation is left unattended or when a shared device is used.

Current Default Configuration

The default SSO session timeout settings are:

Setting

Default Configuration

SSO Session Idle Timeout

30 minutes

SSO Session Maximum Duration

10 hours


Session Idle Timeout

The session idle timeout determines how long a user session can remain inactive before the system automatically logs the user out.

Session Maximum Duration

The session maximum duration defines the maximum length of time a user session can remain active before requiring reauthentication.

Security Considerations

The session timeout settings are implemented as a security measure to help safeguard sensitive employee and payroll information.

Extending the session timeout duration may introduce potential security risks, including:

Unauthorized access from unattended workstations
A user may leave their workstation logged in, allowing unauthorized individuals to access confidential employee information.


Exposure of active sessions on shared or compromised devices
An active session may remain accessible longer than intended, increasing the risk of unauthorized transactions or changes to employee records.


Extended access to sensitive data
If an active session is compromised, unauthorized users may retain access until the session expires.


Requesting a Session Timeout Adjustment

For clients who require a longer session duration due to extended processing activities (such as attendance validation, employee data maintenance, or payroll-related tasks), a Change Request Form (CRF) may be submitted for evaluation.

The CRF request must include acknowledgment and acceptance of the associated security risks.

Configuration Limitations

Please note the following limitations:

  • The maximum configurable SSO Session Idle Timeout is up to 90 minutes.
  • Session idle timeout settings apply to all users and cannot be configured for specific users only.

Want real-time responses? Explore Sidekick, your 24/7 guide for product inquiries!