Workplace sessions

When a user successfully signs in to their digital workplace, they create an active session between their user account and workplace. With an active session, a user can browse and interact with the content of their workplace as permitted by the access rules of the workplace. A user loses this ability to interact with their workplace's access or membership restricted content when their session ends, and they are signed out of their workplace.

Sections in this article:

Multiple sessions

Sessions are handled independently between different web browsers and applications (e.g., Igloo Mobile app, and File Manager). What happens to a session in one application does not affect sessions in any other application.

Session termination

Inactivity

A user's session stays active as long as they are active in their workplace. However, after a period of inactivity, a user's session is terminated, and they will be signed out of their workplace. The length of this inactivity period before a user is signed out is configurable with the configurable Session Timeout setting found in the Control Panel's Sign In Settings page.

Before a user's session is terminated due to inactivity, a dialog prompts users to extend their session. If the user extends their session, the inactivity period is reset; otherwise, their session will be terminated, and they will be signed out of their workplace. This inactivity interval also applies to sessions created in File Manager.

While the Web View tab of the Igloo Mobile app also uses this inactivity period, the Igloo Mobile app does not. As a result, Igloo Mobile app automatically creates a new session for the Web View when the previous one expires due to inactivity.

Close the browser

Sessions can also be configured to terminate when user's close their browser. Browser session termination can be turned on or off in Control Panel's Sign in Settings page. Browser session termination also applies to sessions in the File Manager when users close the app, they are signed out. 

Sign out

Finally, a user can end their session directly by signing out of their workplace:

  • In the browser:
    1. On the Userbar, select your name and then Sign out.
  • In the File Manager: 
    1. Select Main Menu and then Log out of this workplace.
  • In the Mobile App: 
    1. Tap your Profile Photo in the upper-left corner of the app. 
    2. Tap Logout.

Remember Me

If a digital workplace is configured to allow users to select Remember Me before they sign in, users who select this option will have their session last 30 days and won't be signed out due to inactivity. Remember Me can be turned on or off in the Control Panel's Sign in Settings page.

When turned on:

  • Remember Me is only usable by:
    • Users who sign in to their workplace using Igloo Authentication
    • Users who sign in to their workplace using LDAP Authentication
  • Remember Me can only be selected when signing into your workplace using:
    • A web browser
    • File Manager

The Remember Me option found when signing into the Igloo Mobile app functions differently than this. See Signing in to the app.

How single sign-on interacts with workplace sessions

Users who sign in to their digital workplace using single sign-on (SSO) have two sessions to consider:

  • The session with their identity provider (IdP)
  • The session with their digital workplace

In these situations, when a user's session is terminated with their digital workplace, a new session is created if they still have an active session with their IdP. Similarly, if a user's browser already has an active session with their IdP, they will automatically have a workplace session created when they go to their workplace. 

A digital workplace's session will only impact a user's IdP session if the workplace's SAML configuration has a value configured for IdP Logout URL. This setting will cause the user's IdP session, and workplace session to be terminated when they select Sign out. This setting is found on the Control Panel's SAML Configuration page. 

  1. On the Userbar, select Control Panel
  2. Under Membership, select Sign in Settings.
  3. At the bottom of the page, select Configure SAML Authentication