Configure Maximum App Session Lifetime for Okta SAML Applications
Last Updated:
Overview
By default, Okta initiates the Security Assertion Markup Language (SAML) application session, but the application determines the session validity duration. The SessionNotOnOrAfter attribute sends a specific session expiration time to the Service Provider (SP). The SP uses this attribute to manage session validity and terminate the session when the time expires.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Integration Network (OIN)
- Custom SAML Applications
- Single Sign-On (SSO)
Solution
What steps configure the maximum app session lifetime for OIN applications?
Configure the maximum application session lifetime for an Okta Integration Network (OIN) application by adjusting the sign-on settings.
- Navigate to Applications and select the specific application.
- Go to the Sign On tab and select Edit in the Settings section.
- Locate Maximum App Session Lifetime and select Send value in response.
- Enter the desired value.
- Select Save.
Adjusting the advanced SAML settings configures the maximum app session lifetime for custom applications.
Modify the advanced SAML settings to set the maximum application session lifetime for a custom application.
- Navigate to Applications and select the specific application.
- Go to the General tab and locate the SAML Settings section.
- Select Edit, choose Next, and select Show Advanced Settings.
- Locate Maximum App Session Lifetime and select Send value in response.
- Enter the desired value.
- Select Save.
NOTE: Currently, Okta does not support the SessionNotOnOrAfter attribute when acting as a Service Provider (SP).
