Administration Interface Session Timeout

EFT incorporates an internal 15-minute timeout for administration interface connections with PCI DSS-enabled Sites. A warning message and countdown timer appear after 10 minutes of inactivity.

The timer resets if you click Cancel; otherwise, if no activity occurs, the timer expires, and the interface disconnects from EFT. Any non-committed changes are discarded.

This is separate from the Enable Timeout value set for the user and Settings Template.

To change the timeout

  1. In the administration interface, connect to EFT and click the Server tab.

  2. On the Server tab, click the Server node you want to configure, and then click the Administration tab.

  3. Click an EFT-managed administrator account, and then click Account Policy. The Account Security Settings dialog box appears.

  4. Select the Disconnect admin accounts after check box, then specify the minutes of inactivity you need. The timeout is off by default for non-PCI-DSS Sites. Changing the timeout to more than 15 minutes violates PCI DSS 8.5.15, so you will need to document the reason/compensating control if you have a PCI DSS Site.

Related Topics