<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000742q0vSAAOkta Classic EngineMulti-Factor AuthenticationAnswered2026-04-01T09:00:20.000Z2019-11-18T18:52:38.000Z2019-11-27T21:11:37.000Z

xftax (xftax) asked a question.

owa session can be re-opened without authentication

We have found that once we authenticate using Okta mfa, we can close the browser for OWA and within a few minutes re-open the browser and it will still be active without having to re-authenticate. Please explain how to resolve this, or what is going on. Thanks


  • t529b (t529b)

    According to that document, the default session timeout value for OWA is 6 hours, and I verified that our Exchange environment is still set to that value. However, despite periodic reboots, my personal, non-domain-joined machines at home are able to access my company O365 mailbox for many days after authenticating just once. And that includes clients like OWA, Outlook 2016 for Mac, and on my iPhone & iPad using the iOS Outlook client.

     

    I think I'm going to open a support case with Microsoft for this behavior.

    Expand Post
    Selected as Best
  • t529b (t529b)

    With SP-initiated applications like OWA, it's the service provider that is supposed to redirect your browser to Okta to authenticate. Microsoft puts a cookie on your system that controls when OWA will require you to authenticate again, and in my experience, it will go for days or even weeks before forcing my browser to authenticate with Okta again. It's terribly insecure, but I don't think it's a problem that Okta can solve. I have a sign-on rule on our Office 365 integration that is supposed to require MFA on any connection from outside of our corporate network, but it only works when Microsoft redirects a client to Okta to authenticate. If Microsoft doesn't redirect to Okta, then Okta can't present an MFA prompt. If anyone knows of a way to change this behavior, I'd be very interested.

    Expand Post
  • t529b (t529b)

    According to that document, the default session timeout value for OWA is 6 hours, and I verified that our Exchange environment is still set to that value. However, despite periodic reboots, my personal, non-domain-joined machines at home are able to access my company O365 mailbox for many days after authenticating just once. And that includes clients like OWA, Outlook 2016 for Mac, and on my iPhone & iPad using the iOS Outlook client.

     

    I think I'm going to open a support case with Microsoft for this behavior.

    Expand Post
    Selected as Best
This question is closed.
Loading
owa session can be re-opened without authentication