<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7UuLSAVOkta Classic EngineAdministrationAnswered2024-04-30T09:18:25.000Z2015-09-07T23:54:59.000Z2018-08-12T04:15:20.000Z
Best Practice for Session Value & Departing User Workflow
I'm trying to understand the best practice for setting the Okta "Session Lifetime". I understand that the session value can be set between 1 minute and 12 hours. I realize that different…

 

Original Author: Andrew Wild  awild@lancope.com(mailto:awild@lancope.com)

  • j5v7c (j5v7c)

    Hi Andrew,

     

    In the scenario you describe the frequency of your sync jobs (and other org flag settings like federated profiles) will have a big impact and make it nearly impossible to predict the exact behavior thus it is still important to ensure your session lifetime aligns with your security requirements.

     

    As soon as the users account has been deactivated in Okta they will be unable to interact with the Okta UI (existing session or not).

     

    So in your scenario with a 4 hour session.

     

       I login at 8am

       my account (in AD) is disabled at 10 due to termination

       A sync job starts at 10:15 and finishes at 10:30 during which the disabled status is reflected on my okta account

       I click on an application in Okta at 10:31, i am taken to an application specific login page and my primary okta page presents an authentication prompt.

     

    Hope that helps,

     

    -Matt

    Original Author:  Matt Egan  matthew.egan@varian.com(mailto:matthew.egan@varian.com)
    Expand Post
    Selected as Best
  • j5v7c (j5v7c)

    Hi Andrew,

     

    In the scenario you describe the frequency of your sync jobs (and other org flag settings like federated profiles) will have a big impact and make it nearly impossible to predict the exact behavior thus it is still important to ensure your session lifetime aligns with your security requirements.

     

    As soon as the users account has been deactivated in Okta they will be unable to interact with the Okta UI (existing session or not).

     

    So in your scenario with a 4 hour session.

     

       I login at 8am

       my account (in AD) is disabled at 10 due to termination

       A sync job starts at 10:15 and finishes at 10:30 during which the disabled status is reflected on my okta account

       I click on an application in Okta at 10:31, i am taken to an application specific login page and my primary okta page presents an authentication prompt.

     

    Hope that helps,

     

    -Matt

    Original Author:  Matt Egan  matthew.egan@varian.com(mailto:matthew.egan@varian.com)
    Expand Post
    Selected as Best
This question is closed.
Loading
Best Practice for Session Value & Departing User Workflow