Description:

Idle session timeout automatically signs out users from Microsoft 365 web apps after a set period of inactivity.

Why use it?

  • Enhanced Security: Reduces the risk of unauthorized access to data.

  • Data Protection: Safeguards sensitive information when a device is left unattended.

  • Compliance: Helps meet regulatory requirements for session management.

  • Mitigates Risks: Lowers the chance of session hijacking.

Why:

Session lifetimes are an important component in balancing security and the number of times users are prompted for their credentials.

Configured: This setting is in place.

Not Configured: This setting is not in place.

Scoring: Contributes up to 1 point to the Posture Recommendations score.

Category: General

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: YES — Microsoft Secure Score control spo_idle_session_timeout.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • NIST CSF 2.0 — PR.AA-05

  • CIS Microsoft 365 Benchmark v6 (Level 2) — 1.3.2

  • CIS Microsoft 365 Benchmark v7 (Level 2) — 1.3.2

  • HIPAA Security Rule — 164.312(a)(2)(iii)

  • CMMC Level 2 — AC.L2-3.1.11, SC.L2-3.13.9

Microsoft documentation:


_KB status: already published as "Idle Session Timeout" — update the existing step in place._

_Source: Augmentt native check. Check ID activitybasedtimeoutpolicy (module 32)._

Sourced for this page:

  • Secure Score — Microsoft Secure Score control read by Augmentt from Microsoft Graph


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Microsoft 365 Admin · General · M365 Basic · Secure Score · CIS M365 v6 L2 · CIS M365 v7 L2 · NIST CSF 2.0 · HIPAA · CMMC Level 2