Jamf Pro console sessions can end through three distinct pathways, each with different behavioral characteristics and security implications. The following scenarios demonstrate how inactivity timeouts, user-initiated logouts, and system-driven access revocation affect active sessions across the Jamf platform.
User-Initiated (Self-Initiated) Logout
When administrators manually log out of a Jamf product console, the logout process clears the Jamf authentication session for the entire browser profile, affecting most Jamf consoles simultaneously. However, Jamf Pro currently maintains independent session management, and sessions in other browsers or devices remain unaffected until separately terminated. The following diagram shows what happens in the back-end when a user manually logs out of Jamf Pro:
Session Timeout (Inactivity-Based Logout)
Jamf Pro automatically logs out users after periods of inactivity based on timeout settings. While local console sessions expire (typically after 20 minutes), the underlying Jamf authentication service and identity provider sessions may remain active, enabling seamless re-authentication through silent login cookies when users return. The following diagram shows what happens in the back-end when a session times out:
System-Initiated Logout (Admin or Security-Initiated)
Access revocation through identity providers or security events does not immediately terminate active Jamf console sessions. Instead, enforcement relies on the next authentication attempt or natural session expiration, potentially allowing continued access for up to 24 hours until the session timeout occurs or the user attempts to re-authenticate. The following diagram shows what happens in the back-end when a logout is forced by the IdP because of a security event: