Types of Session Lifetime Limits
Session settings apply to the logon pages for the web-based administrative consoles, the command API interface described in the RSA Authentication Manager Developer’s Guide, and the risk-based authentication (RBA) logon attempts by end users. When a session times out or reaches the maximum lifetime, the logon page is redisplayed, and the user must log on again.
You can configure the following settings for sessions:
Time-out. The length of time that a session can be inactive before being terminated. The default setting is 30 minutes.
Maximum Lifetime. The maximum length of an session. When the console session reaches its session lifetime, the session is terminated and the administrator is logged off, regardless of whether the session is active. The default setting is eight hours.
These settings are independent of session inactivity. For example, if a console and command API session lifetime is eight hours, an administrator is automatically logged off after eight hours, even if there have been no periods of inactivity during the session.
Only a Super Admin can modify the console and command API session settings.
Related Tasks
Related Articles
Session Lifetime Limits 52Number of Views Edit Session Lifetime Settings for Operating System Access 22Number of Views Edit Session Lifetime Settings 24Number of Views RSA Passwordless Authentication Succeeds for Initial RDP Logon but Fails When Unlocking the Remote Session 12Number of Views User Sessions 5Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Governance & Lifecycle Generic Database Collector Guide RSA Authentication Manager 8.7 SP2 Administrator's Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager 8.9 Setup and Configuration Guide