Skip to content
ControlVerdict
AC.L2-3.1.11addresses
AC.L2-3.1.11Session Termination
Terminate (automatically) a user session after a defined condition.
  • [a]

    conditions requiring a user session to terminate are defined; and
  • [b]

    a user session is automatically terminated after any of the defined conditions occur.

View full control

Idle and max session lifetimes on VPN and SSO

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. No verdicts yet.

Implementation

AO coverage. Addresses both Session Termination objectives.

VPN. Idle disconnect ≤12 hours; absolute session lifetime forces re-auth. Concurrent sessions limited to one unless ticketed.

SSO. IdP session lifetime for enclave apps is shorter than corporate baseline; sign-out on browser close where supported. Privileged roles already use short PIM activations.

Maintenance. Monthly review of VPN accounts idle >45 days (disable). Quarterly test that an abandoned VPN session cannot be resumed without re-auth.

Accepted gap. One CAD SaaS ignores IdP session length. Compensating control: Conditional Access re-eval on every sensitive action + device compliance.

What the evidence looks like

  • VPN idle/max session configuration
  • IdP session lifetime settings for enclave apps
  • Test ticket for abandoned session re-auth
  • CAD SaaS exception with CA compensating control

Environment

Full-tunnel VPN for lab; SSO for SaaS CUI apps.

Tools

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.