SSO Session Timeout Configuration and Guidelines
Overview
The SSO (Single Sign-On) session timeout settings are security controls designed to protect confidential company and employee information by automatically ending inactive sessions. These settings help prevent unauthorized access, especially when a user’s workstation is left unattended or when a shared device is used.
Current Default Configuration
The default SSO session timeout settings are:
|
Setting |
Default Configuration |
|
SSO Session Idle Timeout |
30 minutes |
|
SSO Session Maximum Duration |
10 hours |
Session Idle Timeout
The session idle timeout determines how long a user session can remain inactive before the system automatically logs the user out.
Session Maximum Duration
The session maximum duration defines the maximum length of time a user session can remain active before requiring reauthentication.
Security Considerations
The session timeout settings are implemented as a security measure to help safeguard sensitive employee and payroll information.
Extending the session timeout duration may introduce potential security risks, including:
Unauthorized access from unattended workstations
A user may leave their workstation logged in, allowing unauthorized individuals to access confidential employee information.
Exposure of active sessions on shared or compromised devices
An active session may remain accessible longer than intended, increasing the risk of unauthorized transactions or changes to employee records.
Extended access to sensitive data
If an active session is compromised, unauthorized users may retain access until the session expires.
Requesting a Session Timeout Adjustment
For clients who require a longer session duration due to extended processing activities (such as attendance validation, employee data maintenance, or payroll-related tasks), a Change Request Form (CRF) may be submitted for evaluation.
The CRF request must include acknowledgment and acceptance of the associated security risks.
Configuration Limitations
Please note the following limitations:
- The maximum configurable SSO Session Idle Timeout is up to 90 minutes.
- Session idle timeout settings apply to all users and cannot be configured for specific users only.
Want real-time responses? Explore Sidekick, your 24/7 guide for product inquiries!