
JosephH.69853 (Customer) asked a question.
I have just installed Okta for O365, and I thought this would mean that my external clients that use the Outlook mobile app on their phone would have to authenticate per our session time out rules. But so far, no clients have been timed out. I decided to delete an email account on my phone and you do get an Okta challenge when you add a company email account to a phone. But you do not get any more challenges from Okta at that point.
How do you get Okta to do a verify after your set session timeout limit? I have to think there is a way to make this happen. But I have not been able to find an answer on Google or in the Okta Knowledgebase.

I accidentally put the wrong topic on this. It is for Okta Identity Engine.
Hi @JosephH.69853 (Customer) , Thank you for reaching out to the Okta Community!
This is the expected behaviour.
Okta does not manage the application time-out and the mobile apps do not log the user out unless it's triggered explicitly, as such Okta would not be trigger any MFA challenge beyond the initial setup.
> side note - We've updated the Question tag for you to reflect OIE.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Community members help others by clicking Like or Select as Best on responses. Try it today.