- SAP S/4HANA Fiori Cloud launchpad is logging off idle user after certain period of time, less than 30 minutes
- SAP S/4HANA Fiori Cloud launchpad is logging off idle user after certain period of time from all SAP Cloud Products, e.g. SuccessFactors
- User logged out even if the "Remember Me" is clicked, they still need to enter their credentials
SAP S/4HANA Cloud 1908
This is independent of existing security sessions the user has based on the configuration and used IDP. Based on the IDP configuration a login screen can open or a security session validation is done in the background. Afterwards the launchpad is opened and displayed again, so that the user can continue working.
- To fulfil security standards within cloud environment the browser session of a user needs to be ended after a certain amount of time
- Within S/4HANA Cloud this timeframe is set to 30 minutes. This timeframe cannot be configured in the current release
- SAP is aware of this situation and plans to enable configuration in one of the upcoming releases
Note: This is impacting SAP S4/HANA Cloud, CEC, IBP
The main impact is that a configuration UI is missing, and this is only the case for NW ABAP Cloud based solutions. For on-premise, this will be delivered with 1909 the first time, but here the timeout can be configured with the normal FLP parameters customizing transactions.
To ensure idle time handling is working correct within Fiori launchpad a certain feature needs to be enabled within the browser settings.
- This feature is called localStorage or DOMStorage depending on the browser vendor
- If the feature is disabled, logoff is performed earlier and not synchronized between different browser tabs or windows
- The synchronization can only be handled within the same browser, not across different browser vendors
Note: Logout is occurring after 30 minutes. This is working as expected to ensure product security. See Cause section for details
Resolution beyond SAP S/4HANA 1905 and SAPUI5 1.65.8 Releases
- With SAP S/4HANA Cloud 1911 the default behavior will be changed so the logout does no longer logout the user from all SAP Product, e.g. SuccessFactors, in case of user inactivity. The logout will only be executed on the SAP S/4HANA Product
The logout will only be executed on the SAP S/4HANA Product.This change will also be available for SAP S/4HANA Cloud 1908 Hot Fix Collection 5 and SAP S/4HANA 1909 with SAPUI5 version 1.65.9 and newer
- Configuration possibility will be introduced for SAP S/4HANA Cloud with 1911 Release
Please refer to the PDF attached to the KBA which is the documentation of the functionality like UI-Driven-Timeout and Server-Driven-Timeout.
timeout FLP cloud s4h, login off FLP S4H , KBA , CA-FLP-FE-COR , Core (Client) , Problem