
xftax (xftax) asked a question.
We have found that once we authenticate using Okta mfa, we can close the browser for OWA and within a few minutes re-open the browser and it will still be active without having to re-authenticate. Please explain how to resolve this, or what is going on. Thanks

According to that document, the default session timeout value for OWA is 6 hours, and I verified that our Exchange environment is still set to that value. However, despite periodic reboots, my personal, non-domain-joined machines at home are able to access my company O365 mailbox for many days after authenticating just once. And that includes clients like OWA, Outlook 2016 for Mac, and on my iPhone & iPad using the iOS Outlook client.
I think I'm going to open a support case with Microsoft for this behavior.