Inconsistencies with "Remember this device for 30 days" Option and Ephemeral Sessions
This article explains why the "Remember this device for 30 days" option does not persist the multi-factor authentication (MFA) state when using ephemeral sessions. End users are prompted for MFA again immediately after closing and reopening the browser, even after selecting the option.
- Ephemeral sessions
- MFA
- Remember this device for 30 days
The tenant session settings, which include Session Expiration and Idle Session Lifetime, apply to both the standard session cookies and the multi-factor authentication (MFA) cookies. The platform does not currently allow for the configuration of different persistence or expiration settings for the main login session cookies versus the MFA cookies. Therefore, the built-in Remember this device option cannot be set to persist the MFA state for 30 days while the main session uses non-persistent ephemeral settings.
The recommended action is to create a feature request to address this limitation.