Hi community,
Wondering if anyone else has experienced a similar issue when updating idle session times. We are attempting to test idle session duration and we are not getting the desired result. We noticed in the Atlassian documentation (linked below) that it states the following -
"When you save changes to the session duration, users don't get logged out of their accounts. The new idle session duration will apply the next time a user logs in."
Prior to resetting sessions for all users in the policy, we tested the following.
Test:
- Updated the idle session duration time to 15 minutes for the desired Auth policy.
- A manual log out from Jira was performed by a user (confirmed auth policy user).
- User then logged back in through SSO, opening Jira in a browser tab.
- One browser window was kept open, logged into Jira. The user moved to another open browser window (not Jira) and waited 20 minutes.
Result: After navigating back to Jira browser window, the session did not timeout or force a new login. They were able to navigate through all actions without being forced to log back in. Nothing changed.
Will the new idle session duration only go into effect when using the Reset Session button in the authentication policy? How would a manual logout be any different, the documentation states - "The new idle session duration will apply the next time a user logs in."
https://support.atlassian.com/security-and-access-policies/docs/update-idle-session-duration/
Thank you.