Okta Session Remains Active When Browser Restores Previous Session
Last Updated:
Overview
When the browser restores the previous session on startup, it retains the Okta session cookies after closure. This occurs because the browser captures a snapshot of the active session, preventing Okta from ending it. Resolve this issue by disabling the browser restore setting via Group Policy or by configuring a shorter idle session timeout in the Okta Admin Console.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Google Chrome
- Microsoft Edge
- Okta Session Lifetime
Cause
When users enable the Google Chrome startup setting Continue where you left off (RestoreOnStartupIsLastSession) or the Microsoft Edge startup setting Open tabs from previous sessions (RestoreOnStartupIsLastSessionAndURL), the browser disables settings that rely on sessions or perform actions on exit. The browser captures a snapshot of all open tabs and active sessions in memory and storage. When the browser reopens, the snapshot loads the valid session ID from Okta, which allows the previous tab to load. Okta cannot force the session to end when users enable these browser settings.
Solution
What is the recommended method to prevent session restoration?
The recommended solution is to disable the browser settings that allow session restoration on shared devices using a group policy or similar management tool. This prevents the flow on shared user devices while allowing user-assigned devices to maintain the current experience. Review the Chrome Enterprise RestoreOnStartup policy documentation for more information regarding this behavior.
Configure the Okta session lifetime as an alternative solution.
If group policies cannot be modified, configure the idle session timeout and maximum lifetime to a low value to invalidate the session after a short period of inactivity. Navigate to the Okta Admin Console, edit the global session policy, and adjust the session management timers.
- Navigate to Security > Global Session Policy.
- Select Edit for the appropriate policy.
- Locate the Okta Global Session Management section.
- Set the idle time or maximum time to a low value (for example, 5 minutes).
