
{"id":1333,"date":"2018-05-09T01:48:01","date_gmt":"2018-05-09T01:48:01","guid":{"rendered":"https:\/\/when2work.com\/help\/mgr\/?page_id=1333"},"modified":"2021-04-08T17:07:17","modified_gmt":"2021-04-08T17:07:17","slug":"security-options","status":"publish","type":"page","link":"https:\/\/when2work.com\/help\/mgr\/security-options\/","title":{"rendered":"Session Security Features"},"content":{"rendered":"<p>When any user logs in, the session created should only be used by that one individual and never shared (just as login details should never be shared).\u00a0 W2W has different security features that assist in this effort, which prevent users from sharing active session links and blocking others from attempting to use the same session on another device or location.\u00a0<\/p>\n<h3>Device-Specific Sessions<\/h3>\n<p>Our system will always attempt to create a device-specific session whenever possible.\u00a0 This is achieved when, upon a successful login from either our secure desktop or mobile login pages, our system places a small plain text file (referred to as a \u2018cookie\u2019) on the device.\u00a0 With device specific sessions, use of the particular session can only be provided if the associated cookie data and browser version are available and verified.\u00a0 Note the cookie data is not used for any other purpose nor tracking, just for identifying if session is being used on same device. <br \/>\n\u00a0<br \/>\nWe offer two different session security levels, and for most organizations we recommend \u201cLevel 2\u201d as that offers the most security while still allowing universal access.\u00a0 Please review the differences offered for each Level below before changing this setting option.<\/p>\n<h3>Level 1<\/h3>\n<p>This lowest level of session security will still attempt to create a device-specific session whenever possible, but if user does not allow cookies it will allow user to continue through a non device-specific session anyway.\u00a0 Also, with this level there is no IP-specific restrictions, so the session can continue if the IP address changes during the session.\u00a0 This level is not recommended unless in extreme case where an organization both requires no cookie use and also has load balancing software that changes IP addresses often.\u00a0<\/p>\n<h3>Level 2<\/h3>\n<p>This level of session security will attempt to create a device-specific session whenever possible, but if the user does not allow cookies it will allow user to continue the session anyway.\u00a0 Any use of a non device-specific desktop session will require a static IP address, so it will block any attempt to use session on a different IP address.\u00a0 Note mobile sessions do not require a static IP address, since cellular data can change address locations, so please see final note below about how to ensure sessions are ended when complete.\u00a0\u00a0 This level is recommended for most organizations as it allows access to all users and ensure will have either device-specific sessions or IP-specific desktop sessions.<\/p>\n<h3>Control the End of a Session<\/h3>\n<p>As a convenience, device-specific sessions do not automatically time out, and non device-specific sessions will time out after 20 minutes of non-use.\u00a0 It is recommended that all users end their sessions by using the \u201cSign Out\u201d option as this ends their particular session so cannot be accessed again, even if attempted from the same device and same IP address.\u00a0 This is critically important when using a shared device.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><span class=\"extrawords\">employee kicked out, expired session, error message kicks me out off<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When any user logs in, the session created should only be used by that one individual and never shared (just as login details should never&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/when2work.com\/help\/mgr\/security-options\/\">More<span class=\"screen-reader-text\">Session Security Features<\/span><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/pages\/1333"}],"collection":[{"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/comments?post=1333"}],"version-history":[{"count":17,"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/pages\/1333\/revisions"}],"predecessor-version":[{"id":7129,"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/pages\/1333\/revisions\/7129"}],"wp:attachment":[{"href":"https:\/\/when2work.com\/help\/mgr\/wp-json\/wp\/v2\/media?parent=1333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}