Session Policy
Configure session timeout, warning, and step-up checks for sensitive admin actions.
Session Policy controls how long users can stay signed in and when Edmissa asks for extra confirmation before sensitive actions. Use it to reduce account risk without making daily work harder than it needs to be.
These settings matter most for admins, managers, and users who handle student profiles, applications, documents, payments, or access settings.
What this guide helps you configure
| Setting area | What it protects |
|---|---|
| Session timeout | Signs users out after the allowed session period. |
| Timeout warning | Gives users a chance to continue before the session ends. |
| Step-up checks | Asks for extra confirmation before sensitive actions. |
Before you start
Prepare these decisions before changing Session Policy:
| Item | Why it matters |
|---|---|
| User working pattern | Counselors may stay in Edmissa for long working sessions. |
| Shared device risk | Offices with shared or public computers need stricter timeout rules. |
| Sensitive actions | Password resets, role changes, exports, and access changes may need extra confirmation. |
| Support plan | Users should know what to do if they are signed out or asked to confirm identity. |
Open Session Policy
Use this path when you want to manage session rules:
- Open Settings.
- Open Security & Sessions.
- Confirm the page title is Session Policy.
The direct route is /t/settings/security/sessions.
Use Save Policy after changing the settings.
Configure visible settings
The Session Policy page shows these settings:
| Setting | How to use it |
|---|---|
| Enable absolute timeout | Turn this on when sessions should end after a fixed period even if the user is active. |
| Show session timeout warning | Turn this on when users should receive a warning before they are signed out. |
| Require step-up for sensitive actions | Turn this on when sensitive actions should ask users to confirm their identity again. |
Use a timeout warning when users complete longer forms or application work. This gives them a chance to continue before the session ends.
Use step-up checks for actions that can affect access, security, or sensitive student work. For example, changing a user's role should be treated more carefully than updating a normal note.
Recommended first version
For a study abroad agency, start with a balanced setup:
- Enable a timeout policy that matches the normal working day.
- Show a timeout warning so users are not surprised during active work.
- Require step-up checks for sensitive actions.
- Tell admins and managers what actions may ask for confirmation.
- Review the policy after users have worked with it for a few days.
Avoid making the first policy too strict. If users are signed out constantly, they may rush work or keep unsafe notes outside the system.
Safe rollout guidance
Before enforcing stricter session rules:
| Step | Why it matters |
|---|---|
| Tell users what will change | Users should understand why they may see warnings or extra checks. |
| Test with one admin account | Confirm admins can still manage users, roles, and settings. |
| Test with one daily user account | Confirm counselors can complete forms and application work. |
| Review support issues | If users are repeatedly blocked, adjust the policy or improve guidance. |
Use stricter rules for higher-risk environments, such as shared office devices or teams with broad access. Use balanced rules for normal daily users so the policy protects work without interrupting every task.
Test after setup
After saving Session Policy:
- Sign in as a test user.
- Confirm normal pages open as expected.
- Wait long enough to confirm timeout behavior.
- Confirm the timeout warning appears if it is enabled.
- Try a sensitive admin action with a test admin.
- Confirm step-up appears only where expected.
- Save a normal student or application update and confirm the workflow still feels usable.
Related guides
| Guide | Use it for |
|---|---|
| Security and audit | Understand how session policy fits with security settings, API access, and audit logs. |
| Users | Manage accounts, passwords, active status, and sessions. |
| Roles | Control which users can perform sensitive actions. |
| Permissions and scope | Understand access level, scope, and system setting access. |
| Access and permissions troubleshooting | Diagnose missing pages, disabled actions, or account access issues. |