Skip to main content
Question

Different session duration for specific users in Universal

  • October 5, 2026
  • 4 replies
  • 37 views

Forum|alt.badge.img

We're running into an issue with session duration. We're currently transitioning from the windows GUI to the universal GUI, and that's where this comes up.

We use entraID as openID provider in IAM, with a session expiration of 30 minutes on the provider. That works fine for most users, but a few users shouldn't be logged out at all during the day.

As far as I can tell, session expiration can be set on 3 levels:
- Global settings
- Per tenant
- Per openid provider

For SSO users only the openid provider setting applies, so I don't see a way to set this per user or per user group.

The only option I've found so far:
2 openid providers with different session expirations.
A second app registration in entra and a second openid provider in IAM with a longer expiration. To avoid two SSO buttons on the login page, each provider gets its own web domain. This should work, but it requires an extra URL, certificate, and it adds extra management overhead for just a small number of users.

My questions:
- Is there another way to set session expiration per user or per user group for SSO users?
- Is what I found a recommended approach, or is there a better alternative?

Thank you in advance!

4 replies

  • Moderator
  • October 5, 2026

Hello Kenny,

It is indeed currently not possible to set session expiration per user, or per user group for that manner.
The workaround you mentioned sounds indeed like something that should work, but I think that there's a simpler solution available to you. If you need to stay signed in for longer than your session expiration, then those users can choose the option 'Keep me signed in’ on the login screen. If the user does need to logout before 'Keep me signed in’ expires, they can just logout and that longer session is removed with it.

Would this suggestion work for you?


Forum|alt.badge.img

Hi Tim,

Thank you for your reply!

I'm not sure this fits for our situation. All our users sign in via entraID/openID, and after the transition to universal, SSO will be the only way to log in. We're aiming for a seamless experience where users open the application and are signed in immediately, without ever seeing a login page.

Because of that, there's no moment where a user could select 'Keep me signed in'. On top of that, I remember reading somewhere that this option isn't available when logging in through an openID provider and that it only works for IAM users, although I might have misread that.


  • Moderator
  • October 5, 2026

Hi Kenny,

You're right. I didn't register that you’re using OpenID Providers, for those the 'Keep me signed in’ option does indeed not have an effect.

At the moment you can set session expiration on three levels: OpenID Provider, Tenant and Global Settings. In my opinion, the two most realistic routes are:

  • The route you've already figured out yourself, of having a second OpenID provider and hiding it by using a second web domain.
  • Depending on the situation can also consider setting the session expiry for everyone (or just that tenant) on 8 hours.

I don’t know your situation but I'd personally probably lean towards the second, as the first solution adds quite a bit of complexity and requires more maintainability efforts (think about DNS records and requesting HTTPS certs.) However, this is something for you to determine.

If you wish for this to be more granular, feel free to create an idea for it.


Arie V
Community Manager
Forum|alt.badge.img+13
  • Community Manager
  • October 5, 2026

​@kennyklootwijk I’d recommend putting the Session duration in IAM to a value that services the users that need to stay logged in the entire day.

Then I’d try and play around with different Conditional Access policies for different Groups/Users in Microsoft Entra to try and enforce different session duration for you 2 groups of users: Configure adaptive session lifetime policies - Microsoft Entra ID | Microsoft Learn