Blog

Announcing a change to Activity Timeout

Author

  • jeff_lakey

    SailPoint

In order to improve our clients’ security posture and adhere to current NIST 800-63 and OWASP standards, Non-Employee Risk Management will be updating authentication settings so that the maximum selectable length of inactivity before timeout is 7 days.

What will be changing?

  • Under Admin -> Authentication -> Sessions -> Activity Timeout, we will be removing the option of “never”.
  • In the same dropdown, we will add an option of “7 days” – this will be the maximum length of application inactivity before users will be required to reauthenticate.
  • As a part of this update, any tenants with Activity Timeout currently set to “never” will be automatically reconfigured to the 7 days option.

Who will be affected by this change?

  • Customers with SSO authentication configured directly from their Identity Provider into Non-Employee Risk Management will see the above change in their tenants.
  • Customers authenticating via Identity Security Cloud will not be affected by this change.

When will this change go into effect?

  • The week of April 15, 2024.