# Device sessions

How long a developer's machine may keep working without signing in again.

## The two settings

**Policy → Device sessions:**

- **Idle timeout (hours)** — a device that has not been used for this long stops working.
- **Max age (days)** — a device stops working this long after enrolment regardless of use.

Leave either blank to switch it off. Both are blank by default.

## How quickly it takes effect

Like manual revocation, expiry takes effect within roughly 30 seconds — the Gateway
notices at the next token refresh rather than at the moment of expiry.

## What the developer sees

Their tools stop working and the Endpoint Suite asks them to sign in again. Nothing is
lost; signing in restores the device.

## Choosing values

Idle timeout is the one that earns its keep: it quietly retires the laptop of the
contractor whose engagement ended, without anyone remembering to do it. A few weeks is
usually right — long enough to survive a holiday, short enough to matter.

Max age is a blunter instrument. It is worth setting if you have a compliance requirement
that says credentials must be re-established periodically; otherwise idle timeout does the
useful part.

Neither is a substitute for offboarding someone who has left. Use **Offboard** for that —
it is immediate and it also removes their passkeys.