Blog
Announcing a change to Activity Timeout
Author
jeff_lakey
SailPoint
In order to improve our clients’ security posture and adhere to current NIST 800-63 and OWASP standards, Non-Employee Risk Management will be updating authentication settings so that the maximum selectable length of inactivity before timeout is 7 days.
What will be changing?
- Under Admin -> Authentication -> Sessions -> Activity Timeout, we will be removing the option of “never”.
- In the same dropdown, we will add an option of “7 days” – this will be the maximum length of application inactivity before users will be required to reauthenticate.
- As a part of this update, any tenants with Activity Timeout currently set to “never” will be automatically reconfigured to the 7 days option.
Who will be affected by this change?
- Customers with SSO authentication configured directly from their Identity Provider into Non-Employee Risk Management will see the above change in their tenants.
- Customers authenticating via Identity Security Cloud will not be affected by this change.
When will this change go into effect?
- The week of April 15, 2024.