timeout settings
Cantor, Scott
cantor.2 at osu.edu
Thu Jun 20 12:48:03 EDT 2019
Also, to add another wrinkle I find quite funny, we all spent 6-7 figures deploying MFA solutions because passwords are so weak, and then proceeded to enable Remember Me features that bypass MFA silently so that any timeouts or SSO bypass rules really only impose the first factor, the password we decided was too weak.
Of course, people do apply policies to block Remember Me on shared machines by...yes, network ranges. So that's why I focus on that these days, despite the obvious limitations. The IdP can do that just as well.
-- Scott
More information about the users
mailing list