Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-816

Allow Session Duration for Mobile apps to be managed by Organization admins

    • 37
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Suggestion

      As per Session duration management - Atlassian Documentation, Accounts on Mobile apps will not be affected.

      It would be good to include the mobile app platform's idle Session Duration to be managed by the Organization admin.

            [ACCESS-816] Allow Session Duration for Mobile apps to be managed by Organization admins

            Hi everyone, 

            We have released the feature which enable the org admins to manage the session duration for mobile apps . 

            More here - https://support.atlassian.com/security-and-access-policies/docs/set-mobile-app-session-expiration/

             

            Kunwardeep Singh added a comment - Hi everyone,  We have released the feature which enable the org admins to manage the session duration for mobile apps .  More here - https://support.atlassian.com/security-and-access-policies/docs/set-mobile-app-session-expiration/  

            In Prod.

            Minh hung Nguyen added a comment - In Prod.

            @Minh, please see my feedback to @Derrick on https://support.atlassian.com/requests/JST-977790 as this is relevant to that issue

            tom.hawkins added a comment - @Minh, please see my feedback to @Derrick on https://support.atlassian.com/requests/JST-977790 as this is relevant to that issue

            The lack of the session time out is causing a severe security risk. I don't think user expectation is relevant in this case. Every company has its own security policies and staying logged in is out of the question, especially on mobile devices. This is the weakest link in your security policy as per website you can enforce session time out and with that a new login including MFA. Please get this on your backlog soon and fix it.

            Jeroen Smulders added a comment - The lack of the session time out is causing a severe security risk. I don't think user expectation is relevant in this case. Every company has its own security policies and staying logged in is out of the question, especially on mobile devices. This is the weakest link in your security policy as per website you can enforce session time out and with that a new login including MFA. Please get this on your backlog soon and fix it.

            We can now vote for this issue again so I encourage everyone to ask as many colleague's to vote.

            Faroek Sweet added a comment - We can now vote for this issue again so I encourage everyone to ask as many colleague's to vote.

            Phil Yeo added a comment - - edited

            Totally unacceptable that you are leaving a known vulnerability as "won't" fix. This results in the org being unable to terminate access to users with mobile app access. Has the Atlassian Security team signed off on this decision?

            Phil Yeo added a comment - - edited Totally unacceptable that you are leaving a known vulnerability as "won't" fix. This results in the org being unable to terminate access to users with mobile app access. Has the Atlassian Security team signed off on this decision?

            nojansen added a comment -

            It is very disappointing that this issue has been closed as won't do. 

            One of the benefits of Cloud products is mobile access. From an IT security perspective, the Idle Session Duration NEEDS to be controlled by the organizations admins.

            nojansen added a comment - It is very disappointing that this issue has been closed as won't do.  One of the benefits of Cloud products is mobile access. From an IT security perspective, the Idle Session Duration NEEDS to be controlled by the organizations admins.

              ea199a4e80cb Minh hung Nguyen
              ashohaimi Syauqi (Inactive)
              Votes:
              56 Vote for this issue
              Watchers:
              35 Start watching this issue

                Created:
                Updated:
                Resolved: