Dec 14, 2025

Enable idle session timeout in Microsoft 365

4 min readBeginner

When a user walks away and leaves a Microsoft 365 web app open in the browser, the session stays live and the screen becomes a security risk. Idle session timeout signs users out of Office web apps automatically after a set period of inactivity, so the data on that screen is protected when the person is not there. The feature is turned on once and applies to the whole tenant. In this guide you will learn how to enable idle session timeout in the Microsoft 365 admin center.

What idle session timeout does

The idle session timeout is a tenant-wide policy. When it is enabled, Microsoft 365 signs users out of the supported web apps after the configured period of inactivity. A few important facts to know before you turn it on:

Behavior Result
Scope Applies to all users in the tenant; it cannot target specific users or groups
Desktop and mobile apps Not affected by the timeout
Existing timeout policies The Microsoft 365 setting overrides the Outlook on the web and SharePoint timeout policies

Which web apps are covered

The timeout applies to the browser versions of the main Microsoft 365 services. Confirm that the apps you care about are in the supported list before enabling the policy.

Supported web apps Included
Outlook on the web Yes
OneDrive for Business Yes
SharePoint Online Yes
Word, Excel, and PowerPoint on the web Yes
Microsoft 365 home and start pages Yes
Microsoft 365 Admin Center Yes
Microsoft Defender portal Yes
Microsoft Purview compliance portal Yes
Azure portal Yes

Enable idle session timeout in the admin center

Turn the feature on under organization settings. The change applies to the whole tenant and takes effect for the supported web apps immediately.

1
Open organization settings

Sign in to the Microsoft 365 admin center, expand Settings, and click Org settings.
2
Open the Security and privacy tab

Click the tab, then choose Idle session timeout.
3
Turn the policy on

Check the box to turn on idle session timeout for Office web apps.
4
Choose the time interval

Pick a preset from the dropdown, or choose custom and type the number of minutes.
5
Save the setting

Click Save to apply the policy to the tenant.
Microsoft 365 admin center Idle session timeout settings with the turn on checkbox and the time interval dropdown

Choose the time interval

The dropdown offers preset intervals. If none of the presets matches your requirement, use the custom option and set the timeout in minutes.

Interval Notes
Preset values One hour, two hours, four hours, eight hours, and twelve hours
Custom Any value between 5 and 1440 minutes

What users see when the timeout fires

Users do not lose their work silently. The browser warns before the session ends, then signs the user out.

Message When it appears
Your session is about to expire Shortly before the configured timeout, giving the user a chance to continue
You have been signed out After the inactivity period passes and the session ends

Verify the timeout policy

Open a supported web app in a browser, wait for the configured inactivity period, and confirm the sign-out page appears. On the Microsoft 365 web apps the policy is active immediately after you save the admin center setting.

Frequently asked questions

What does the idle session timeout do?

It signs users out of Microsoft 365 web apps after a period of inactivity, protecting sensitive data on unattended screens.

Can I enable it for specific users only?

No. The idle session timeout is a tenant-wide policy and applies to all users in the organization.

Does it affect desktop and mobile apps?

No. Only the supported web apps in the browser are covered by the timeout.

What is the longest interval I can set?

With the custom option you can set up to 1440 minutes, which is 24 hours. The shortest allowed value is 5 minutes.

What should I tell users before enabling it?

Let them know they will be signed out after a period of inactivity, and that unsaved work in a web app should be saved before the warning appears.