Okta Long Running Sessions

Last updated
Detects users with long-running sessions in Okta, defined as more than 7 days. Extremely long sessions without re-authentication pose a security threat and can increase the chance of session hijacking.
Recommended Actions
Clear the end user sessions to require re-authentication.
Review your Okta session lifetime policies and consider setting a maximum session lifetime of 16 hours with a 2-hour idle timeout to reduce the risk of session hijacking from long-lived sessions.
Compatibility

Last updated