Salesforce CRM:The Definitive Admin Handbook(Third Edition)
上QQ阅读APP看书,第一时间看更新

Session timeout

There are various features that can be used to set the session timeout as per the following sections.

Timeout value

Timeout value sets the length of time after which inactive users are automatically logged out of the system. The options are between 15 minutes and 12 hours.

Note

As a system administrator, you need to balance the requirements for user satisfaction and the enforcement of security controls; however, it is recommended that you choose as short a timeout period as possible to protect sensitive information and enforce stricter security.

The value of the last active session is not updated until halfway through the timeout period. So, if you have a 2-hour timeout, the system does not check for activity until 1 hour has passed. As an example, say, you have a 2-hour timeout value. If you update a record after 30 minutes, the last active session value is not updated because there was no activity after 1 hour and hence, you will still be logged out in another 1 hour and 30 minutes, because the last active session has not been updated.

Disable session timeout warning popup

The Disable session timeout warning popup feature sets whether inactive users are presented with a timeout warning message. Users are warned 30 seconds before the session timeout, as set by the timeout value.

Force logout on session timeout

Enabling Force logout on session timeout option causes inactive users to have their browsers refreshed and set to the Salesforce.com login page when the session times out.

Note

It is recommended that you do not select Disable session timeout warning popup when enabling the Force logout on the session timeout feature.