Azure P2S VPN (Entra ID Auth) Session/Idle Timeout Policy and Configuration

Witsanu Ratreeswad 0 Reputation points
2025-12-12T04:33:07.4266667+00:00

Dear Microsoft Support Team,

I am seeking official clarification regarding the Session Timeout and Idle Timeout policies for our Point-to-Site (P2S) VPN connections terminating on Azure Virtual WAN (vWAN).

  1. VPN Type: P2S via Azure Virtual WAN
  2. Authentication Method: Microsoft Entra ID

We need confirmation on the following:

  1. Is there an Azure-enforced Session Lifetime or Idle Disconnect Timeout for P2S connections?
  2. If such a timeout exists, what are the default values, and what is the official documentation for extending this duration to ensure continuous operation for our users (e.g., aiming for 24-hour sessions)?

Please direct us to the relevant documentation or assist us in verifying the configuration on our VPN Gateway/vWAN setup.

Azure Virtual WAN
Azure Virtual WAN
An Azure virtual networking service that provides optimized and automated branch-to-branch connectivity.
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2025-12-12T04:33:29.7566667+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    For Azure Point-to-Site (P2S) VPN connections using Microsoft Entra ID authentication, there are specific considerations regarding session and idle timeout policies:

    1. Session Lifetime and Idle Disconnect Timeout: The default lifetime for refresh tokens used in Microsoft Entra ID authentication is 90 days. However, the refresh tokens can expire sooner based on conditional access policies set by your Entra tenant administrators. These policies can enforce reauthentication every few hours, which effectively impacts session continuity.
    2. Extending Timeout Duration: To ensure continuous operation for your users, you can work with your Entra tenant administrators to adjust the sign-in frequency by adding conditional access policies. This can help extend the refresh token expiration interval, allowing for longer sessions. For detailed guidance on configuring these settings, you can refer to the Microsoft documentation on Refresh tokens in the Microsoft identity platform and Configure adaptive session lifetime policies.

    For specific configurations on your VPN Gateway or vWAN setup, you may need to verify the settings directly in the Azure portal or through Azure PowerShell commands.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.