---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Define active session timeout exception roles \[New in Security Center 1.3\]

# Define active session timeout exception roles \[New in Security Center 1.3\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use a system property to exempt roles from active session timeout limits.
Use the glide.active.session.timeout.exception.roles system property to exempt roles from an active session timeout limit. The active session timeout feature helps ensure that a hijacked session cannot be used
indefinitely without providing authentication information. It is best practice to only consider an active session timeout limit exception for internal integration account roles.

Configure the glide.active.session.timeout.exception.roles property to roles which should be exempt from active session timeouts. This property value is a comma separated list of roles. The default value is
edge_encryption,mid_server,maint.

## More information {#sc-define-active-session-timeout-exception-roles__section_qhx_1b1_xwb}

{#sc-define-active-session-timeout-exception-roles__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.active.session.timeout.exception.roles |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | string |
| Recommended value | edge_encryption,mid_server,maint |
| Default value | edge_encryption,mid_server,maint |
| Fallback value | edge_encryption,mid_server,maint |
| Category | [Session management](https://servicenow-prod.fluidtopics.net/VAFB7gAR3D02VvnVYJ_a3g "This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.") |
| Security risk | * Severity score: 6.4 * CVSS score: Medium * Consider an active session timeout limit exception only for internal integration account roles. If a user is a victim of a session hijacking attempt, and has a role with an exception, attackers using that session can continue to authenticate to that session indefinitely. This may increase the impact of a security incident by enabling an attacker more time to make use of a hijacked account. {#sc-define-active-session-timeout-exception-roles__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-define-active-session-timeout-exception-roles__table_ajc_b43_3kb}

