AC.L2-3.1.11Session Termination
Terminate (automatically) a user session after a defined condition.
[a]
conditions requiring a user session to terminate are defined; and[b]
a user session is automatically terminated after any of the defined conditions occur.
Idle and max session lifetimes on VPN and SSO
Implementation
AO coverage. Addresses both Session Termination objectives.
VPN. Idle disconnect ≤12 hours; absolute session lifetime forces re-auth. Concurrent sessions limited to one unless ticketed.
SSO. IdP session lifetime for enclave apps is shorter than corporate baseline; sign-out on browser close where supported. Privileged roles already use short PIM activations.
Maintenance. Monthly review of VPN accounts idle >45 days (disable). Quarterly test that an abandoned VPN session cannot be resumed without re-auth.
Accepted gap. One CAD SaaS ignores IdP session length. Compensating control: Conditional Access re-eval on every sensitive action + device compliance.
What the evidence looks like
- VPN idle/max session configuration
- IdP session lifetime settings for enclave apps
- Test ticket for abandoned session re-auth
- CAD SaaS exception with CA compensating control
Environment
Tools
Was this example useful?
Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.
Discussion(0)
No discussion on this example yet
Verdicts capture a conclusion. Use a thread when the interesting part is the argument.
Sign in to start a thread.