Custom Session Policies give administrators greater control over how long users remain signed in to their Haiilo environment.
By configuring separate session settings for web and mobile applications, organizations can align authentication behavior with their internal security, compliance, and usability requirements.
Whether your organization prefers shorter or longer session durations, Custom Session Policies provide the flexibility to define session behavior based on your specific needs.
This feature is available as part of the Advanced Security Add-on. Please contact your personal Account Manager for further information.
What are Custom Session Policies?
Custom Session Policies allow administrators to configure how long users can remain authenticated before being required to sign in again.
The feature provides separate controls for web and mobile applications, allowing organizations to balance security and user convenience across different usage scenarios.
Custom Session Policies help organizations:
- Align session behaviour with internal security policies
- Balance security and user convenience
- Configure web and mobile sessions independently
- Reduce the risk associated with long-lived sessions
- Support different security requirements for different usage patterns
Understanding session settings
Custom Session Policies provide four independent settings that can be configured separately for web and mobile users.
| Setting | Description |
|---|---|
| Web Session Idle Time | Determines how long a user can remain inactive in the web application before being required to sign in again. User activity resets the idle timer. |
| Web Session Maximum Duration | Determines the maximum lifetime of a web session. Once this limit is reached, the user must sign in again regardless of activity. |
| Offline / Mobile Session Idle Time | Determines how long a user can remain inactive in the mobile application before re-authentication is required. |
| Offline / Mobile Session Maximum Duration | Determines the maximum lifetime of a mobile session. Once reached, users must authenticate again even if they remain active. |
Supported configuration ranges:
- Session Idle Time: 1 hour to 30 days
- Session Maximum Duration: 1 day to Unlimited
These limits apply to both web and mobile sessions and help ensure configured values remain within supported and practical ranges.
How do I configure Custom Session Policies?
To configure session policies:
- Open Administration.
- Navigate to Authentication.
- Open the Advanced tab.
- Configure the desired values for:
- Web Session Idle Time
- Web Session Maximum Duration
- Offline / Mobile Session Idle Time
- Offline / Mobile Session Maximum Duration
- Save your changes.
Security best practices
When configuring session policies, consider both your organization's security requirements and user experience.
- Review session policies periodically.
- Consider both inactivity timeouts and maximum session durations.
- Communicate major policy changes to users before implementation.
- Combine session policies with Multi-Factor Authentication for stronger account protection.
Frequently asked questions
- Yes. Web and mobile session policies are fully independent and can be configured separately. This allows organizations to implement different authentication strategies depending on how users access the platform.
- Idle time measures how long a session can remain inactive before expiring.
Maximum duration measures the total lifetime of a session regardless of activity.
Even if a user remains active, a session expires once its maximum duration has been reached. - Yes. Maximum session duration can be configured as Unlimited.
- The minimum supported idle timeout for both web and mobile sessions is 1 hour.
- The maximum supported idle timeout for both web and mobile sessions is 30 days.
- Yes. All four settings are configured independently, allowing organizations to define separate session policies for web and mobile access.