Device sessions
How long a developer's machine may keep working without signing in again.
The two settings
Policy → Device sessions:
- Idle timeout (hours) — a device that has not been used for this long stops working.
- Max age (days) — a device stops working this long after enrolment regardless of use.
Leave either blank to switch it off. Both are blank by default.
How quickly it takes effect
Like manual revocation, expiry takes effect within roughly 30 seconds — the Gateway notices at the next token refresh rather than at the moment of expiry.
What the developer sees
Their tools stop working and the Endpoint Suite asks them to sign in again. Nothing is lost; signing in restores the device.
Choosing values
Idle timeout is the one that earns its keep: it quietly retires the laptop of the contractor whose engagement ended, without anyone remembering to do it. A few weeks is usually right — long enough to survive a holiday, short enough to matter.
Max age is a blunter instrument. It is worth setting if you have a compliance requirement that says credentials must be re-established periodically; otherwise idle timeout does the useful part.
Neither is a substitute for offboarding someone who has left. Use Offboard for that — it is immediate and it also removes their passkeys.