For the complete documentation index, see llms.txt. This page is also available as Markdown.

Okta Long Running Sessions

Detects users with long-running sessions in Okta, defined as more than 7 days. Extremely long sessions without re-authentication pose a security threat and can increase the chance of session hijacking.

Recommended Actions

Clear the end user sessions to require re-authentication.

Review your Okta session lifetime policies and consider setting a maximum session lifetime of 16 hours with a 2-hour idle timeout to reduce the risk of session hijacking from long-lived sessions.

Compatibility

Okta

Last updated