Entra ID Long Running Sessions
Last updated
Detects users with long-running sessions in Entra ID, defined as more than 90 days (configurable). Only alerts on sessions that don't have any authentication record in the last 30 days (configurable). Extremely long sessions without re-authentication pose a security threat and can increase the chance of session hijacking.
Recommended Actions
Clear the end user sessions to require re-authentication. We recommend setting "Maximum Entra ID session lifetime" to 16 hours (one working day) and "Expire session after user has been idle on Entra ID for" to 2 hours.
Default Check Settings
Session Length Threshold Days: 90
Days Since Last Recorded Authentication: 30
Compatibility
Last updated