Description:
Idle session timeout automatically signs out users from Microsoft 365 web apps after a set period of inactivity.
Why use it?
Enhanced Security: Reduces the risk of unauthorized access to data.
Data Protection: Safeguards sensitive information when a device is left unattended.
Compliance: Helps meet regulatory requirements for session management.
Mitigates Risks: Lowers the chance of session hijacking.
Why:
Session lifetimes are an important component in balancing security and the number of times users are prompted for their credentials.
Configured: This setting is in place.
Not Configured: This setting is not in place.
Scoring: Contributes up to 1 point to the Posture Recommendations score.
Category: General
Microsoft Licensing: Works with Basic licensing
Secure Score Impact: YES — Microsoft Secure Score control spo_idle_session_timeout.
Remediation in Augmentt: Configure directly in Augmentt (Configure tab)
Compliance Frameworks:
NIST CSF 2.0 — PR.AA-05
CIS Microsoft 365 Benchmark v6 (Level 2) — 1.3.2
CIS Microsoft 365 Benchmark v7 (Level 2) — 1.3.2
HIPAA Security Rule — 164.312(a)(2)(iii)
CMMC Level 2 — AC.L2-3.1.11, SC.L2-3.13.9
Microsoft documentation:
_KB status: already published as "Idle Session Timeout" — update the existing step in place._
_Source: Augmentt native check. Check ID activitybasedtimeoutpolicy (module 32)._
Sourced for this page:
Secure Score — Microsoft Secure Score control read by Augmentt from Microsoft Graph
Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft 365 Admin · General · M365 Basic · Secure Score · CIS M365 v6 L2 · CIS M365 v7 L2 · NIST CSF 2.0 · HIPAA · CMMC Level 2
