Requiring reauthentication for new and expired sessions for a SAML SSO authentication service

To add an extra layer of security, you configure Pega Platform to reauthenticate new sessions and to reauthenticate when reactivating an expired session. The timeout period is specified on the operator's access group or is managed by the application server or another external facility.

  1. Open the authentication service and on the SAML 2.0 tab, navigate to the Advanced configuration settings section.
  2. Select the Use Access group timeout check box to use the authentication timeout values specified in the user access groups to determine how long a user session remains inactive before users are prompted to identify themselves again. Clear this check box if timeout is managed by the application server or another external facility.
  3. To require reauthentication for new and reactivated sessions, select the Force authentication check box.
  4. Click Save.
What to do next:  Configuring operator provisioning for a SAML SSO authentication service