last sync: 2024-Sep-19 17:51:32 UTC

Microsoft Managed Control 1054 - Session Termination | Regulatory Compliance - Access Control

Azure BuiltIn Policy definition

Source Azure Portal
Display name Microsoft Managed Control 1054 - Session Termination
Id 5807e1b4-ba5e-4718-8689-a0ca05a191b2
Version 1.0.0
Details on versioning
Versioning Versions supported for Versioning: 0
Built-in Versioning [Preview]
Category Regulatory Compliance
Microsoft Learn
Description Microsoft implements this Access Control control
Additional metadata Name/Id: ACF1054 / Microsoft Managed Control 1054
Category: Access Control
Title: Session Termination
Ownership: Customer, Microsoft
Description: The information system automatically terminates a user session after Customer users: logout request initiated by user; service team user: logout request initiated by service team user or 15 minutes of inactivity.
Requirements: Azure automatically terminates Microsoft user sessions upon receiving a logout request from the user. Secure Admin Workstations (SAWs) require reauthentication after at most ten (10) minutes of user inactivity. VPN The SAW VPN terminates inactive sessions after three hundred sixty (360) minutes of inactivity, and the non-SAW VPN terminates inactive sessions after sixty (60) minutes of inactivity. Servers RDP and SSH idle timeout inherit the settings of the target server. Azure servers are configured to terminate idle sessions after fifteen (15) minutes of inactivity. Network Devices SSH idle timeout inherits the settings of the target network device. Azure network devices are configured to terminate inactive sessions after sixty (60) minutes.
Mode Indexed
Type Static
Preview False
Deprecated False
Effect Fixed
audit
RBAC role(s) none
Rule aliases none
Rule resource types IF (2)
Microsoft.Resources/subscriptions
Microsoft.Resources/subscriptions/resourceGroups
Compliance Not a Compliance control
Initiatives usage none
History none
JSON compare n/a
JSON
api-version=2021-06-01
EPAC