Device sessions

How long a developer's machine may keep working without signing in again.

The two settings

Policy → Device sessions:

Leave either blank to switch it off. Both are blank by default.

How quickly it takes effect

Like manual revocation, expiry takes effect within roughly 30 seconds — the Gateway notices at the next token refresh rather than at the moment of expiry.

What the developer sees

Their tools stop working and the Endpoint Suite asks them to sign in again. Nothing is lost; signing in restores the device.

Choosing values

Idle timeout is the one that earns its keep: it quietly retires the laptop of the contractor whose engagement ended, without anyone remembering to do it. A few weeks is usually right — long enough to survive a holiday, short enough to matter.

Max age is a blunter instrument. It is worth setting if you have a compliance requirement that says credentials must be re-established periodically; otherwise idle timeout does the useful part.

Neither is a substitute for offboarding someone who has left. Use Offboard for that — it is immediate and it also removes their passkeys.


Revision #6
Created 2026-08-02 10:20:04 UTC by Sentilai Docs
Updated 2026-08-04 08:39:49 UTC by Sentilai Docs