---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Limit policy based session access mobile refresh token interval \[New in Security Center 1.5\]

# Limit policy based session access mobile refresh token interval \[New in Security Center
1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use the glide.authenticate.session_access.mobile.refresh_token_interval property to govern the length of time that must elapse before a mobile device user will be forced to re-authenticate.
A user will be asked to re-authenticate only if the admin has configured the Identity Provider attributes in the session policy (attributes can vary each login), and the user authenticates using Single Sign On (SSO). The
default value represents the time in seconds that a user has before being re-authenticated. A larger default value provides a bad actor more time for session access in the event of a session hijacking.

## More information {#sc-limit-policy-based-session-access-mobile-refresh__section_more_information}

{#sc-limit-policy-based-session-access-mobile-refresh__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.authenticate.session_access.mobile.refresh_token_interval |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | integer |
| Recommended value | 1800 (seconds) |
| Default value | 1800 (seconds) |
| Category | [Session management](https://servicenow-prod.fluidtopics.net/VAFB7gAR3D02VvnVYJ_a3g "This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.") |
| Security risk | * Severity score: 4.3 * CVSS score: Medium * Security risk details: If the ZTA policy is enabled on the instance, then users who are using SSO during mobile login will be forced to logout and re-login after the default value of 1800 seconds (30 minutes) have eclipsed. If a higher value is used, then users will be forced to wait that elapsed time. {#sc-limit-policy-based-session-access-mobile-refresh__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | Zero Trust- Policy Based Session Access |
| Functional impact | This setting governs the time in seconds after login, that users will be forced to logout from mobile devices if they are using Single Sign On to authenticate, and admin has configured the Identify provider attributes in the session access policy. |
[ ]

{#sc-limit-policy-based-session-access-mobile-refresh__table_ajc_b43_3kb}

