> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/okta-long-running-sessions.md).

# Okta Long Running Sessions

Detects users with long-running sessions in Okta, defined as more than 7 days. Extremely long sessions without re-authentication pose a security threat and can increase the chance of session hijacking.

**Recommended Actions**

Clear the end user sessions to require re-authentication.

Review your Okta session lifetime policies and consider setting a maximum session lifetime of 16 hours with a 2-hour idle timeout to reduce the risk of session hijacking from long-lived sessions.

**Compatibility**

[Okta](/integrations/okta-data-integration.md)

<figure><img src="/files/NE7KxvrvJ1cL40UVLucR" alt=""><figcaption></figcaption></figure>

<br>
