We're running into an issue with session duration. We're currently transitioning from the windows GUI to the universal GUI, and that's where this comes up.
We use entraID as openID provider in IAM, with a session expiration of 30 minutes on the provider. That works fine for most users, but a few users shouldn't be logged out at all during the day.
As far as I can tell, session expiration can be set on 3 levels:
- Global settings
- Per tenant
- Per openid provider
For SSO users only the openid provider setting applies, so I don't see a way to set this per user or per user group.
The only option I've found so far:
2 openid providers with different session expirations.
A second app registration in entra and a second openid provider in IAM with a longer expiration. To avoid two SSO buttons on the login page, each provider gets its own web domain. This should work, but it requires an extra URL, certificate, and it adds extra management overhead for just a small number of users.
My questions:
- Is there another way to set session expiration per user or per user group for SSO users?
- Is what I found a recommended approach, or is there a better alternative?
Thank you in advance!

