RapidIdentity is preconfigured to allow inactive user sessions to maintain session context for up to 8 hours. This default setting enables students and teachers to authenticate once at the beginning of the school day without needing to reauthenticate until the next day.
Seamless Learning Access automatically refreshes an inactive user's SSO session context when needed. You can reduce the default inactivity time to align with security best practices without affecting the user experience.
NIST SP 800-53 Control AC-12 mandates automatic session termination after a defined period of user inactivity. Although the specific time is organization-defined, industry standards often set timeouts to 15 minutes for general systems and 5 minutes for high-security, sensitive applications.
Access to your RapidIdentity administrator portal
- Navigate to your RapidIdentity administrator portal.
- From the module selector, choose .
- In the General section, click Settings.
- Click the Authentication tab.
- In the Minutes of inactivity before session expiration field, enter the number of minutes RapidIdentity should wait before expiring an inactive user's session.
- Click Save.