--- title: "Sign out idle SSO user" slug: "team-account-idle-timeout" description: "Enhance security with Document360's idle SSO team account logout feature, preventing unauthorized access and ensuring confidentiality in your projects." updated: 2026-09-13T11:43:42Z published: 2026-09-13T11:43:42Z canonical: "docs.document360.com/team-account-idle-timeout" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.document360.com/llms.txt > Use this file to discover all available pages before exploring further. # Sign out idle SSO user The **Sign out idle SSO user** feature automatically signs out SSO users who have been inactive in the Knowledge base portal for a defined period of time. This reduces the risk of unauthorized access on unattended sessions and gives administrators control over how long idle sessions remain open. The feature applies to SAML and OpenID Connect configurations only and does not affect standard Document360 user accounts. --- ## Before you begin - Your project must have SSO configured using SAML or OpenID Connect. - You must have the **Owner** or **Admin** project role to edit SSO configurations. NOTE This setting applies only to SSO users. It does not affect regular Document360 users. --- ## How to enable sign out for idle SSO users 1. Navigate to **Settings** () in the left navigation bar of the Knowledge base portal. 2. In the left navigation pane, go to **Users & permissions** > **SSO Configuration**. 3. Hover over the SSO configuration you want to update and click the **Edit** () icon. 4. In the configuration panel, navigate to the **More settings** tab. 5. Turn on the **Sign out idle SSO user** toggle. 6. In the **Timeout duration** field, enter your desired idle timeout in **hours:minutes** format. The maximum timeout duration you can set is 23 hours and 59 minutes. 7. Click **Save**. ![SSO configuration settings with highlighted options for signing out idle users and timeout duration.](https://cdn.document360.io/860f9f88-412e-4570-8222-d5bf2f4b7dd1/Images/Documentation/Screenshot-SSO_configuration_idle_user_signout.png) Once saved, SSO users who remain inactive for the configured duration will be automatically signed out and required to log in again. --- ## Best practices - Set the timeout duration based on how sensitive the content in your knowledge base is. For internal projects with confidential content, a shorter timeout (for example, 30 minutes to 1 hour) is recommended. - Inform your SSO users that an idle timeout is in place so they are not caught off guard if they are signed out mid-session. - The default timeout duration is 2 hours. If this suits your project's needs, you do not need to adjust it. --- ## FAQ **What happens when a user is signed out due to inactivity?** The user will be required to log in again via SSO to regain access to the Knowledge base portal. **Is there a default idle timeout duration?** Yes. The default duration is 2 hours. You can adjust this to any value that suits your project's requirements. **What is the maximum idle timeout duration I can set?** You can set the idle timeout to any duration up to a maximum of 23 hours and 59 minutes.