SAP Knowledge Base Article - Public

2685240 - Session timeout message - System behaviour when SSO SAML v2 is enabled

Symptom

  • What is the behaviour when a user’s session times out?
  • Can we set a redirect for when a user’s session times out?
  • Can we force the user’s IdP session to be terminated when the SuccessFactors session expires?

"Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental."

Environment

SAP SuccessFactors HCM Suite

Reproducing the Issue

  1. A user’s session has timed out.
  2. They are prompted with the below pop-up with the message: "Your session has expired. If you have any unsaved data, close this message and copy the data before logging in again. If not, please log in again now."

Session Timeout.png

Cause

  • The SuccessFactors BizX suite has a hard default setting of 30 minutes timeout on no activity.
  • This applies to all cloud clients and cannot be changed at all, no exceptions as there is no instance level capability.
  • See KBA 2088893 - System: 30 minute Session Timeout - BizX Platform

Resolution

The user has two options.

  • Clicking "Close" 
    • The user’s session in SuccessFactors has expired, but the IdP session remains active.
    • If the user clicks the “Close” button, the page they are currently on will remain available in read-only mode.

OR

  • Clicking "Login"
    • The user’s session in SuccessFactors has expired, but the IdP session remains active.
    • If the user clicks “Login”, they will be redirected to the session-timeout redirect URL configured in provisioning. Refer to KBA 2278269

Note:

  • If there is no session timeout redirect URL configured in provisioning and the user clicks "Login", users will be redirected to the default company login screen.
  • If a customized timeout is configured in the instance, the SLO (single logout) will be triggered instead of the timeout dialog. In this case, no Login/Close pop-up appears at the end of the session. This is expected behavior, and if the timeout is reverted to the default value, the session-timeout pop-up and the respective redirection should work as expected.

Keywords

Session timeout, redirect, re-direct, start page, login page, error, session, timed, "Your session has expired. If you have any unsaved data, close this message and copy the data before logging in again. If not, please log in again now.", , KBA , LOD-SF-PLT-SEL , SSO Errors & Logs , Problem

Product

SAP SuccessFactors HCM Suite all versions