Enable idle session timeout in Microsoft 365
When a user walks away and leaves a Microsoft 365 web app open in the browser, the session stays live and the screen becomes a security risk. Idle session timeout signs users out of Office web apps automatically after a set period of inactivity, so the data on that screen is protected when the person is not there. The feature is turned on once and applies to the whole tenant. In this guide you will learn how to enable idle session timeout in the Microsoft 365 admin center.
What idle session timeout does
The idle session timeout is a tenant-wide policy. When it is enabled, Microsoft 365 signs users out of the supported web apps after the configured period of inactivity. A few important facts to know before you turn it on:
Which web apps are covered
The timeout applies to the browser versions of the main Microsoft 365 services. Confirm that the apps you care about are in the supported list before enabling the policy.
Enable idle session timeout in the admin center
Turn the feature on under organization settings. The change applies to the whole tenant and takes effect for the supported web apps immediately.
Choose the time interval
The dropdown offers preset intervals. If none of the presets matches your requirement, use the custom option and set the timeout in minutes.
What users see when the timeout fires
Users do not lose their work silently. The browser warns before the session ends, then signs the user out.
Verify the timeout policy
Open a supported web app in a browser, wait for the configured inactivity period, and confirm the sign-out page appears. On the Microsoft 365 web apps the policy is active immediately after you save the admin center setting.
Frequently asked questions
What does the idle session timeout do?
It signs users out of Microsoft 365 web apps after a period of inactivity, protecting sensitive data on unattended screens.
Can I enable it for specific users only?
No. The idle session timeout is a tenant-wide policy and applies to all users in the organization.
Does it affect desktop and mobile apps?
No. Only the supported web apps in the browser are covered by the timeout.
What is the longest interval I can set?
With the custom option you can set up to 1440 minutes, which is 24 hours. The shortest allowed value is 5 minutes.
What should I tell users before enabling it?
Let them know they will be signed out after a period of inactivity, and that unsaved work in a web app should be saved before the warning appears.
