STIGQter STIGQter: STIG Summary: Microsoft Intune MDM Service Desktop & Mobile Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Microsoft Intune service must initiate a session lock after a 15-minute period of inactivity.

DISA Rule

SV-273867r1207980_rule

Vulnerability Number

V-273867

Group Title

SRG-APP-000003-UEM-000003

Rule Version

MSIN-25-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Sign in to portal.office365.com (or .us if the user is a GCCH or DOD tenant).

1. Navigate to Admin >> Settings >> Org Settings >> Security and Privacy (tab on top of page) >> Idle Session Timeout.
2. Select the check box to enable "Turn on to set the period of inactivity".
3. Select custom option, then enter "15".
4. Select "Save".

Check Contents

To verify the inactivity timeout is configured for 15 minutes or less, follow the steps outlined below:

1. Sign in to portal.office365.com (or .us if the user is a GCCH or DOD tenant).
2. Navigate to Admin >> Settings >> Org Settings >> Security and Privacy (tab on top of page) >> Idle Session Timeout.
3. Select the check box to enable "Turn on to set the period of inactivity".
4. Select custom option, then verify it has been set to 15.

If the inactivity timeout is not set to 15 minutes or less, this is a finding.

Vulnerability Number

V-273867

Documentable

False

Rule Version

MSIN-25-000030

Severity Override Guidance

To verify the inactivity timeout is configured for 15 minutes or less, follow the steps outlined below:

1. Sign in to portal.office365.com (or .us if the user is a GCCH or DOD tenant).
2. Navigate to Admin >> Settings >> Org Settings >> Security and Privacy (tab on top of page) >> Idle Session Timeout.
3. Select the check box to enable "Turn on to set the period of inactivity".
4. Select custom option, then verify it has been set to 15.

If the inactivity timeout is not set to 15 minutes or less, this is a finding.

Check Content Reference

M

Target Key

5699