Zpa Create Timeout Policy Rule

作者 zscaler809f68d6c921無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Create ZPA timeout policy rules that control session re-authentication and idle timeout behavior. Configures how long a user session remains active (reauth_timeout) and how long an idle session persists (reauth_idle_timeout) before requiring re-authentication. Supports conditions: APP, APP_GROUP, CLIENT_TYPE, SAML, SCIM, SCIM_GROUP, PLATFORM, and POSTURE. Use when an administrator asks: 'Set session timeout', 'Configure idle timeout', 'Require re-authentication after X hours', or 'Set different timeouts per app or user group.'

AI 產生的概覽

建立 ZPA 逾時原則規則,為應用程式與使用者群組設定工作階段重新驗證與閒置逾時時間。

功能
此技能引導管理員建立 ZPA 逾時原則規則,用來定義已驗證工作階段的有效時長(reauth_timeout),以及閒置連線在要求重新驗證前的持續時間(reauth_idle_timeout)。文件說明了支援的取值格式、基準建議、支援的條件類型(APP、APP_GROUP、CLIENT_TYPE、SAML、SCIM、SCIM_GROUP、PLATFORM、POSTURE),以及查詢與建立所需的工具呼叫。產出為一筆已建立的逾時原則規則及一次驗證查詢,並附有針對網段群組、承包商、SAML 使用者、平台、終端狀態及組合條件的範例。
適用情境
當管理員要求設定工作階段逾時、設定閒置逾時、要求在指定時間後重新驗證,或針對不同應用程式或使用者群組套用不同逾時值時使用。適用於需要建立並驗證逾時規則的 ZPA 原則管理工作。
執行需求
需要存取 ZPA 管理工具,包括列出網段群組與應用程式網段、查詢 SCIM 群組、SAML 屬性與終端狀態設定檔、建立逾時原則規則,以及取得規則進行驗證的工具。不隨附指令碼,僅為說明文件。

ZPA: Create Timeout Policy Rule

Keywords

timeout policy, session timeout, idle timeout, reauth timeout, re-authentication, session expiry, idle disconnect, timeout rule, session duration, zpa timeout, reauth policy

Overview

Create ZPA timeout policy rules that define session re-authentication and idle timeout behavior. Timeout policies control how long a user's authenticated session remains valid and how long an idle connection persists before requiring re-authentication. Different applications and user groups can have different timeout values.

Use this skill when: An administrator asks to configure session timeouts, set idle disconnect timers, require re-authentication after a specific period, or apply different timeout rules to different applications or user groups.


Timeout Parameters

reauth_timeout (Session Timeout)

How long a user session remains valid before requiring re-authentication, regardless of activity.

Value FormatExamplesDescription
<number> Minutes"30 Minutes", "60 Minutes"Session expires after N minutes
<number> Hours"4 Hours", "8 Hours"Session expires after N hours
<number> Days"1 Days", "10 Days", "30 Days"Session expires after N days
Never"Never"Session never expires (not recommended for sensitive apps)

Minimum: 10 minutes. Default: "172800" (seconds, i.e., 2 days).

reauth_idle_timeout (Idle Timeout)

How long an idle (inactive) connection persists before the session is terminated.

Value FormatExamplesDescription
<number> Minutes"10 Minutes", "30 Minutes"Idle session expires after N minutes
<number> Hours"1 Hours", "2 Hours"Idle session expires after N hours
<number> Days"1 Days"Idle session expires after N days
Never"Never"Idle sessions never expire

Minimum: 10 minutes. Default: "600" (seconds, i.e., 10 minutes).

Action

The only supported action is RE_AUTH -- when the timeout is reached, the user must re-authenticate.


Baseline Values (recommended)

Reference: ZPA Baseline Recommendations v1.0 §Timeout Policies Recommendations.

Authentication timeout (reauth_timeout)

ProfileValueRationale
Default — high-security environment"24 Hours"Daily MFA / SSO revalidation.
Default — convenience-focused"3 Days" to "7 Days"Lower friction for low-risk tenants.
Service accounts (documented exception)"30 Days" or "Never"Only with explicit security exception and inventory tracking.

Apply a single global authentication-timeout rule and add narrow per-group exceptions only when justified.

Idle timeout (reauth_idle_timeout) — per app class

App classValueWhy
Non-sensitive apps"15 Minutes" to "30 Minutes"Frees connector resources, low security risk.
Sensitive apps (Finance, HR, regulated)"10 Minutes" to "15 Minutes"Tighter idle window for crown-jewel apps.
Long-lived sessions (RDP, SSH, DB)"30 Minutes" to "60 Minutes"Avoids dropping interactive shells mid-session.
Background services / API agents / monitoring"Never"Disable idle so automated clients don't reconnect on every poll.

Anti-pattern: Avoid reauth_idle_timeout below "10 Minutes" — causes constant tunnel reconnects and poor user experience.


Condition Object Types

Timeout policies support a subset of condition types.

Value-Based (use values)

Object TypeDescriptionValues
APPApplication segmentsApplication segment IDs
APP_GROUPSegment groupsSegment group IDs
CLIENT_TYPEClient connector typezpn_client_type_zapp, zpn_client_type_exporter, zpn_client_type_browser_isolation, zpn_client_type_ip_anchoring, zpn_client_type_edge_connector, zpn_client_type_branch_connector, zpn_client_type_zapp_partner

Entry-Values Based (use entry_values with lhs/rhs)

Object TypeLHSRHS
SAMLSAML attribute IDAttribute value to match
SCIMSCIM attribute header IDAttribute value to match
SCIM_GROUPIdentity Provider IDSCIM group ID
PLATFORMlinux, android, ios, mac, windows"true" or "false"
POSTUREPosture profile posture_udid"true" or "false"

Workflow

Step 1: Gather Requirements

Ask the administrator:

Required:

  • Rule name
  • Session timeout value (e.g., "8 Hours", "30 Days", "Never")
  • Idle timeout value (e.g., "30 Minutes", "1 Hours", "Never")

Optional:

  • Description
  • Which applications or segment groups to scope to
  • Which users/groups this applies to
  • Platform restrictions
  • Posture requirements

Common scenarios:

  • "Sessions should expire after 8 hours for all apps" -> global timeout rule
  • "Sensitive apps should have a 30-minute idle timeout" -> scoped to APP_GROUP
  • "Contractors should re-authenticate every 4 hours" -> scoped to SCIM_GROUP
  • "Mobile devices should have shorter timeouts" -> scoped to PLATFORM

Step 2: Look Up Required IDs

For application scoping:

text
zpa_list_segment_groups()zpa_list_application_segments()```text
**For identity conditions:**
```textget_zpa_scim_group(search="<group_name>")get_zpa_saml_attribute(search="<attribute_name>")```text
**For posture profiles:**
```textget_zpa_posture_profile(search="<profile_name>")```text
---
### Step 3: Create the Rule
```textzpa_create_timeout_policy_rule(  name="<rule_name>",  action_type="RE_AUTH",  reauth_timeout="<session_timeout>",  reauth_idle_timeout="<idle_timeout>",  description="<description>",  conditions=<conditions_payload>)```text
---
### Step 4: Verify
```textzpa_get_timeout_policy_rule(rule_id="<returned_rule_id>")```text
---
## Ready-to-Use Examples
### Example 1: Standard Timeout for a Segment Group
Set 8-hour session timeout and 30-minute idle timeout for internal applications.
**Step 1: Find the segment group**
```textzpa_list_segment_groups()```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule(  name="Standard Timeout - Internal Apps",  action_type="RE_AUTH",  reauth_timeout="8 Hours",  reauth_idle_timeout="30 Minutes",  description="Standard session and idle timeouts for internal applications",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<internal_apps_segment_group_id>"]        }      ]    }  ])```text
---
### Example 2: Strict Timeout for Sensitive Applications
Short session timeout (4 hours) and aggressive idle timeout (10 minutes) for sensitive apps.
```textzpa_create_timeout_policy_rule(  name="Strict Timeout - Sensitive Apps",  action_type="RE_AUTH",  reauth_timeout="4 Hours",  reauth_idle_timeout="10 Minutes",  description="Short timeouts for sensitive/high-security applications",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<sensitive_apps_segment_group_id>"]        }      ]    }  ])```text
---
### Example 3: Contractor-Specific Timeout
Contractors must re-authenticate every 4 hours with a 15-minute idle timeout.
**Step 1: Look up contractor group**
```textget_zpa_scim_group(search="Contractors")```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule(  name="Contractor Timeout",  action_type="RE_AUTH",  reauth_timeout="4 Hours",  reauth_idle_timeout="15 Minutes",  description="Shorter session for contractor accounts",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "SCIM_GROUP",          "entry_values": [            {"lhs": "<idp_id>", "rhs": "<contractors_scim_group_id>"}          ]        }      ]    }  ])```text
---
### Example 4: Long Timeout with SAML + Segment Group
Allow a 10-day session for specific SAML-identified users on a specific segment group.
**Step 1: Look up IDs**
```textget_zpa_saml_attribute(search="Email_Users")zpa_list_segment_groups()```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule(  name="Extended Timeout - VIP Users",  action_type="RE_AUTH",  reauth_timeout="10 Days",  reauth_idle_timeout="1 Hours",  description="Extended session for VIP users accessing standard apps",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "SAML",          "entry_values": [            {"lhs": "<saml_email_attr_id>", "rhs": "[email protected]"},            {"lhs": "<saml_email_attr_id>", "rhs": "[email protected]"}          ]        }      ]    }  ])```text
**Logic:** User must be accessing apps in the segment group AND have a matching SAML email.
---
### Example 5: Platform-Specific Timeout
Mobile devices (Android/iOS) get shorter timeouts than desktops.
**Mobile rule (stricter):**
```textzpa_create_timeout_policy_rule(  name="Mobile Timeout - Short",  action_type="RE_AUTH",  reauth_timeout="4 Hours",  reauth_idle_timeout="15 Minutes",  description="Shorter timeouts for mobile devices",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "android", "rhs": "true"},            {"lhs": "ios", "rhs": "true"}          ]        }      ]    }  ])```text
**Desktop rule (more relaxed):**
```textzpa_create_timeout_policy_rule(  name="Desktop Timeout - Standard",  action_type="RE_AUTH",  reauth_timeout="10 Days",  reauth_idle_timeout="1 Hours",  description="Standard timeouts for desktop devices",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "mac", "rhs": "true"},            {"lhs": "windows", "rhs": "true"},            {"lhs": "linux", "rhs": "true"}          ]        }      ]    }  ])```text
---
### Example 6: Posture-Based Timeout
Devices that pass a posture check get a longer timeout; non-compliant devices get a shorter one.
**Step 1: Look up posture profile**
```textget_zpa_posture_profile(search="CrowdStrike_ZTA")```text
**Compliant devices (longer timeout):**
```textzpa_create_timeout_policy_rule(  name="Compliant Device Timeout",  action_type="RE_AUTH",  reauth_timeout="30 Days",  reauth_idle_timeout="2 Hours",  description="Extended timeout for posture-compliant devices",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "POSTURE",          "entry_values": [            {"lhs": "<posture_udid>", "rhs": "true"}          ]        }      ]    }  ])```text
**Non-compliant devices (shorter timeout):**
```textzpa_create_timeout_policy_rule(  name="Non-Compliant Device Timeout",  action_type="RE_AUTH",  reauth_timeout="1 Hours",  reauth_idle_timeout="10 Minutes",  description="Aggressive timeout for non-compliant devices",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "POSTURE",          "entry_values": [            {"lhs": "<posture_udid>", "rhs": "false"}          ]        }      ]    }  ])```text
---
### Example 7: Combined Conditions -- Group + App + Platform
Engineering team accessing sensitive apps from Linux gets a specific timeout.
```textzpa_create_timeout_policy_rule(  name="Engineering Linux Timeout",  action_type="RE_AUTH",  reauth_timeout="12 Hours",  reauth_idle_timeout="45 Minutes",  description="Custom timeout for Engineering on Linux accessing sensitive apps",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<sensitive_apps_segment_group_id>"]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "SCIM_GROUP",          "entry_values": [            {"lhs": "<idp_id>", "rhs": "<engineering_group_id>"}          ]        }      ]    },    {      "operator": "OR",      "operands": [        {          "object_type": "PLATFORM",          "entry_values": [            {"lhs": "linux", "rhs": "true"}          ]        }      ]    }  ])```text
---
## Timeout Strategy Guide
| Use Case | reauth_timeout | reauth_idle_timeout | Rationale ||---|---|---|---|| Standard office apps | 8-10 Hours | 30-60 Minutes | Covers a workday without constant re-auth || Sensitive/compliance apps | 2-4 Hours | 10-15 Minutes | Frequent re-auth for high-security apps || Contractors / third parties | 4 Hours | 15 Minutes | Reduced trust, tighter controls || Mobile devices | 4-8 Hours | 15-30 Minutes | Higher risk of device loss || Desktop on corporate network | 10-30 Days | 1-2 Hours | Low risk, high convenience || Non-compliant devices | 1-2 Hours | 10 Minutes | Encourage compliance || Development/test environments | 30 Days / Never | 2 Hours | Minimize developer friction |
---
## Edge Cases
### No Conditions (Global Default)
A rule with no conditions applies as the default timeout for all users and applications:
```textzpa_create_timeout_policy_rule(  name="Global Default Timeout",  action_type="RE_AUTH",  reauth_timeout="8 Hours",  reauth_idle_timeout="30 Minutes",  conditions=[])```text
### Never Expire
For development or test environments where re-authentication is disruptive:
```textzpa_create_timeout_policy_rule(  name="Dev Environment - No Timeout",  action_type="RE_AUTH",  reauth_timeout="Never",  reauth_idle_timeout="Never",  conditions=[    {      "operator": "OR",      "operands": [        {          "object_type": "APP_GROUP",          "values": ["<dev_segment_group_id>"]        }      ]    }  ])```text
Not recommended for production applications.
### Listing Existing Timeout Rules (opt-in)
Do **not** pre-list timeout rules before every create. New ZPA timeoutrules are appended at the end of the policy by default; pre-listingadds a round trip, gives no useful information for the typical case,and invites fan-out retries when the list comes back empty on a freshtenant.
Run the listing **only** when the admin explicitly asks about ordering,duplicate names, or wants to inspect existing rules:
```textzpa_list_timeout_policy_rules()```text
---
## Quick Reference
**Tools used:**
- `zpa_list_segment_groups()` -- find segment group IDs- `zpa_list_application_segments()` -- find application segment IDs- `get_zpa_scim_group(search)` -- look up SCIM group IDs- `get_zpa_saml_attribute(search)` -- look up SAML attribute IDs- `get_zpa_posture_profile(search)` -- look up posture profile UDIDs- `zpa_create_timeout_policy_rule(name, action_type, reauth_timeout, reauth_idle_timeout, conditions)` -- create the rule (no pre-flight needed)- `zpa_list_timeout_policy_rules()` -- **only** when the admin explicitly asks about ordering or wants to inspect existing rules- `zpa_get_timeout_policy_rule(rule_id)` -- verify the rule
**Timeout format:** `"<number> Minutes"`, `"<number> Hours"`, `"<number> Days"`, `"Never"`
**Action:** `RE_AUTH` (only supported action)
**Condition logic:**
- Multiple condition blocks = AND (all must match)- Multiple entry_values within a block = OR (any can match)- Separate condition blocks per object type

來源與署名

來源:zscaler/zscaler-mcp-server位於skills/zpa/create-timeout-policy-rule提交809f68d

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架