Remaining logged in to any website for a long period of time increases your risk of a cyber attack. To help your organization stay safe, the KnowBe4 console has built-in absolute session limits. However, you can set additional session limits in your Account Settings.
Absolute Session Limits
All admin console and Learner Experience (LX) sessions are limited to 12 hours. If a user has been logged in for nearly 12 hours, a notification prompts them to log out before the session ends. If the user doesn't log out, the session will end and they'll be asked to log in again to continue. 
If an LX session is ending and a user clicks on the Start button of a training assignment, a pop-up notification will display. The user will be asked to log out and log back in before starting the training. 
Inactive admin console and LX sessions will timeout after eight hours. After eight hours of inactivity, the user will be logged out. When the user returns, they'll be asked to log in again. 
Inactive Session Timeout Options
You can shorten the inactive session limit of your users by following the steps below:
- Log in to your KnowBe4 console.
- In the top-right corner, click your email address and select Account Settings.
- Navigate to User Management > the User Settings. In the Security Settings section, you’ll see the following options for session timeout limits:
- The Admin Session Timeout drop-down menu limits the length of all inactive admin console sessions. Admins will be logged out after they have been inactive for the amount of time selected from the drop-down menu. The default setting is eight hours.
- The User Session Timeout drop-down menu limits the length of all inactive LX sessions. Users will be logged out after they have been inactive for the amount of time selected from the drop-down menu. The default setting is eight hours.
- Once you've set your session timeouts, save these options by clicking Save Changes at the bottom of the page.
Simultaneous Sessions
A simultaneous session is when an admin or user is logged in to the KnowBe4 console from multiple locations at the same time. Simultaneous sessions can put your platform at risk of being accessed by cybercriminals. For an added layer of security, we recommend using the features listed in the subsections below.
Log Out of Simultaneous Sessions
Admins and users can manually log out of all of their current sessions from their account by following the steps below:
- In the top-right corner of your KnowBe4 console, click your name or email address.
- Select Profile.
- Click Log Out of All Sessions at the bottom of the page.
- You'll immediately be logged out of the KnowBe4 console.
Limit Sessions to Specific IP Ranges
You can adjust your settings so that admins and Security Role users can't access the console from an IP address outside a specified range by following the steps below:
- Log in to your KnowBe4 console.
- In the top-right corner, click your email address and select Account Settings.
- Navigate to User Management > User Settings.
- In the Security Sessions section, select the Only allow console sessions from specific IP ranges check box.
-
Enter the IP ranges from which you would like to allow admins and Security Role users to access the console.
Important:You must also enter your own public IP address in order for the setting to be saved. - Click Save Changes at the bottom of the page.
Prevent Simultaneous Sessions
You can prevent admins and security role users from having simultaneous console sessions on multiple IP addresses.
- Log in to your KSAT console.
- In the top-right corner, click your email address and select Account Settings.
- Navigate to the User Settings subsection under User Management.
- Select the Limit a user's console sessions to one IP address check box to enable this setting.
- Click Save Changes at the bottom of the page.