SAP Knowledge Base Article - Public

2794310 - SAP S/4HANA Fiori cloud launchpad is logging off idle user after in less than 30 minutes

Symptom

  • SAP S/4HANA Fiori Cloud launchpad is logging off idle user after certain period of time, less than 30 minutes
  • SAP S/4HANA Fiori Cloud launchpad is logging off idle user after certain period of time from all SAP Cloud Products, e.g. SuccessFactors
  • User logged out even if the "Remember Me" is clicked, they still need to enter their credentials

Environment

SAP S/4HANA Cloud 1908

Cause

This is independent of existing security sessions the user has based on the configuration and used IDP. Based on the IDP configuration a login screen can open or a security session validation is done in the background. Afterwards the launchpad is opened and displayed again, so that the user can continue working.

  • To fulfil security standards within cloud environment the browser session of a user needs to be ended after a certain amount of time 
  • Within S/4HANA Cloud this timeframe is set to 30 minutes. This timeframe cannot be configured in the current release
  • SAP is aware of this situation and plans to enable configuration in one of the upcoming releases

Note: This is impacting SAP S4/HANA Cloud, CEC, IBP

The main impact is that a configuration UI is missing, and this is only the case for NW ABAP Cloud based solutions. For on-premise, this will be delivered with 1909 the first time, but here the timeout can be configured with the normal FLP parameters customizing transactions.

Resolution

To ensure idle time handling is working correct within Fiori launchpad a certain feature needs to be enabled within the browser settings.

  • This feature is called localStorage or DOMStorage depending on the browser vendor
  • If the feature is disabled, logoff is performed earlier and not synchronized between different browser tabs or windows
  • The synchronization can only be handled within the same browser, not across different browser vendors

Note: Logout is occurring after 30 minutes. This is working as expected to ensure product security. See Cause section for details

Resolution beyond SAP S/4HANA 1905 and SAPUI5 1.65.8 Releases

  • With SAP S/4HANA Cloud 1911 the default behavior will be changed so the logout does no longer logout the user from all SAP Product, e.g. SuccessFactors, in case of user inactivity. The logout will only be executed on the SAP S/4HANA Product
  • The logout will only be executed on the SAP S/4HANA Product.This change will also be available for SAP S/4HANA Cloud 1908 Hot Fix Collection 5 and SAP S/4HANA 1909 with SAPUI5 version 1.65.9 and newer

  • Configuration possibility will be introduced for SAP S/4HANA Cloud with 1911 Release

See Also

Please refer to the PDF attached to the KBA which is the documentation of the functionality like UI-Driven-Timeout and Server-Driven-Timeout.

Keywords

timeout FLP cloud s4h, login off FLP S4H , KBA , CA-FLP-FE-COR , Core (Client) , Problem

Product

SAP S/4HANA Cloud 1908

Attachments

Sign_Out.pdf