Configure Admin Console session lifetime

Early Access release

This configuration affects only the Okta Admin Console. Administrative sessions in other Okta

applications are unaffected, including Okta Workflows, Okta Access Gateway, and Advanced Server Access.

You can change the session lifetime and idle time for the Okta Admin Console. These settings are independent of those set for Okta sign-on policies. See Configure an Okta sign-on policy.

  1. In the Admin Console, go to ApplicationsApplications.

  2. Click Okta Admin Console.

  3. On the Sign On tab, click Edit in the Okta Admin Console session section.

  4. Set the Maximum app session lifetime in hours or minutes.

    Okta recommends 12 hours based on US National Institute of Standards and Technology (NIST) guidance. The maximum time allowed is 24 hours, the minimum is 1 minute.

    The maximum session lifetime must be equal to or greater than the configured idle time.

  5. Set the Maximum app session idle time in hours or minutes.

    Okta recommends 15 minutes based on US National Institute of Standards and Technology (NIST) guidance. The maximum time allowed is 2 hours, the minimum is 1 minute.

    For settings over 10 minutes, a popup appears within 5 minutes of the timeout with a link to reset the time. For settings under 10 minutes, the popup appears within 30 seconds of the timeout.

    The idle expiration time resets based on your interactions within the Admin Console.

  6. Click Save.