By default, the refresh token has a 7-day lifetime, enabling secure access without
frequent logins. Users receive a notification on their Prisma Access Agent app 60
minutes before token expiration.
Notification Process
The user is notified of the impending token expiration based on what is configured in
the
Notify Before Session Expires and
Session
Timeout Expiration Message setting in the
Prisma Access Agent
app settings. If no message has been
configured, then the system will show a generic notification indicating that the
session is about to
expire.
For example, 60 minutes before token expiration, the user will receive an OS
notification (desktop notifications must be enabled in this case). The following
image is an example of the OS notification on a macOS desktop device.
When the user clicks on the OS notification, the Prisma Access Agent app opens
showing a notification banner at the bottom of the window. (The message on the
banner isn’t configurable.) The user merely has to click the notification banner to
start a new session.
SAML Authentication Workflow
If you configured the agent to use SAML authentication, if the user's identity
provider (IdP) session is active, authentication with the agent continues without
user action. When the user clicks the notification banner, the banner is removed
from the app. In the background, the agent initiates SAML authentication but will
remain in the connected state so that the agent and gateway are still connected. The
agent then reauthenticates with the server, gets a new gateway token, and
reestablishes the tunnel.
For expired IdP sessions, users will need to complete the SAML authentication flow to
renew their session. The system default browser or
Prisma Access Agent
embedded browser will open to redirect the user to their organization’s login page
where they can proceed with authenticating with their organization.
After successful authentication, the user will be connected to the Prisma Access Agent.
(Prisma Access Agent 25.3.0.43)
LDAP Authentication Workflow
If you're using LDAP authentication, if the
user's LDAP credential are still active, authentication with the agent continues
without user action. When the user clicks the notification banner, the banner is
removed from the app. In the background, the agent initiates LDAP authentication but
will remain in the connected state so that the agent and gateway are still
connected. The agent then reauthenticates with the server, gets a new gateway token,
and reestablishes the tunnel.
If the user's LDAP credentials have expired,
they will need to reenter their login credentials to authenticate with the LDAP
server. After successful authentication, the user will be connected to the Prisma Access Agent.