1.1.16 Ensure the option to remain signed in is hidden

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The option for the user to Stay signed in or the Keep me signed in option will prompt a user after a successful login, when the user selects this option a persistent refresh token is created. Typically this lasts for 90 days and does not prompt for sign-in or Multi-Factor.

Rationale:

Allowing users to select this option presents risk, especially in the event that the user signs into their account on a publicly accessible computer/web browser. In this case it would be trivial for an unauthorized person to gain access to any associated cloud data from that account.

Impact:

Once this setting is hidden users will no longer be prompted upon sign-in with the message Stay signed in?. This may mean users will be forced to sign in more frequently. Important: some features of SharePoint Online and Office 2010 have a dependency on users remaining signed in. If you hide this option, users may get additional and unexpected sign in prompts.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To verify the option to remain signed in is disabled, use the Microsoft 365 Admin Center:

Log in to https://admin.microsoft.com as a Global Administrator.

Go to Admin centers and click on Azure Active Directory, once in the AD Admin Center select Azure Active Directory.

Under Manage select Company branding followed by the appropriate Locale policy.

If no policy exists you will need to click Configure to create one

Scroll to the bottom of the newly opened pane and ensure Show option to remain signed in is not checked.

Click Save.

Default Value:

Users may select stay signed in

See Also

https://workbench.cisecurity.org/files/4073