- Welcome to the New-Scale Security Operations Platform
- Licenses
- Supported Regions for Data Residency
- Get Started with the New-Scale Security Operations Platform
- Universal Role-Based Access
- Exabeam Nova
- Monitoring
- Export Your Exabeam Data
Configuring Tenant Session Timeout
Overview
To provide organizations with greater flexibility and control over their security posture, Administrators and Security Engineers can configure a custom session timeout duration for their specific tenant.
You can tailor your session lengths to meet your exact operational needs, whether that means shortening the timeout to meet heightened security and compliance controls, or extending it to support continuous visibility for Security Operations Center displays.
Important Considerations
Before modifying your session timeout settings, please review the following parameters:
Allowed Range: The minimum allowed duration is 1 hour, and the maximum is 24 hours.
Scope of Enforcement: Once applied, the configured session duration is enforced for all standard users within that tenant.
Roles: Only Administrator and Security Engineer roles can configure session timeouts.
Default Value: If no custom value is set, the session timeout defaults to 4 hours.
Caution
Extending the access-token lifetime beyond the 4-hour default increases the window in which a stolen or exposed token may be misused. Users who select a longer duration, up to 24 hours, are responsible for evaluating and accepting the associated security risk.
How to Configure Session Timeout
Log in to your tenant and navigate to Settings.
Under Team, select Single Sign-On/MFA.
Locate the Session Timeout configuration field.
Enter your desired timeout duration in hours or combination of hours and minutes. (must be between
1and24hours).Save your changes. The new session timeout will take effect for all users upon their next login.