2.2.10 [RFC3501] Section 5.4, Autologout Timer


The specification states: "If a server has an inactivity autologout timer, the duration of that timer MUST be at least 30 minutes."

Microsoft Exchange Server 2007, Microsoft Exchange Server 2010, Microsoft Exchange Server 2013, Microsoft Exchange Server 2016

Microsoft Exchange Server has an inactivity autologout timer with a default duration of 30 minutes, but can be configured to use a duration of less than 30 minutes.


The specification does not describe any other required or optional autologout timers.

Exchange 2007, Exchange 2010, Exchange 2013, Exchange 2016

Microsoft Exchange implements an unauthenticated timer, which limits the duration of an unauthenticated session. The default duration of the unauthenticated timer is 60 seconds, but Microsoft Exchange can be configured to use a duration of less than 60 seconds. The receipt of any command from the client during that interval does not reset the unauthenticated timer.