'Don't ask for MFA' reverting after 60 mins

SNAdmin47
Kilo Sage

Hi, 

 

We use MFA for external customers which works fine but we've recently noticed that when the 'Don't challenge for MFA on this browser for the next 8 hours' tickbox is ticked it only works for 1 hour, i.e., it won't challenge for MFA for the first hour but will then revert and challenge for MFA after 1 hour has passed. As per the MFA properties product doc I've checked the sys_property 'glide.authenticate.multifactor.browser.fingerprint.validity' and this is set to 8 which should be effective for 8 hours, and the sys_property 'glide.authenticate.multifactor.remember.browser.enable' is also set to truehttps://www.servicenow.com/docs/bundle/utah-platform-security/page/integrate/authentication/referenc...

 

Is anybody able to confirm if this is expected behaviour or if there's potentially something else I can check or refer to to restore the 8 hour MFA fingerprint validity? Our session timeout is set to 60 mins, so I was wondering if that has an impact but it seems unlikely since I've tested on our dev instance and reduced the session timeout to 5 mins and it worked fine. 

 

Many thanks in advance, any help would be greatly appreciated!

2 ACCEPTED SOLUTIONS

Hello @SNAdmin47 

 

Sure, do let me know.

 

Kindly mark my answer as helpful and accept solution if it helped you in anyway,

 

Regards,

Shivalika 

 

My LinkedIn - https://www.linkedin.com/in/shivalika-gupta-540346194

 

My youtube - https://youtube.com/playlist?list=PLsHuNzTdkE5Cn4PyS7HdV0Vg8JsfdgQlA&si=0WynLcOwNeEISQCY

View solution in original post

Hi @Ankur Bawiskar  My colleague still has an open ticket for it and is still awaiting feedback from the business stakeholders, but we've advised them that from the disparity in our testing with different browsers, and also using different security settings and versions on browsers, we believe this is most likely due to browser configuration. 

View solution in original post

11 REPLIES 11

Sarah Barnes
Tera Contributor

I will also be interested in the outcome of this case, as I have had a couple of customers complain about this that when they go back into the portal it re-asks! 

 

Hi @Sarah Barnes , no further input from me I'm afraid. We never got a definitively proven outcome but we have a strong suspicion that the change in expected behaviour is driven by the browser settings and preferences as we've seen different behaviours being exhibited by different users/sources.