Timeout Settings for Angular Apps
Zendesk Ticket: 396349
Account: Las Vegas Convention & Visitors Authority (LVCVA)
Region: US
Articles used in your research: Configure the Idle Timeout
General:
Business impact if not resolved: Unsecure sessions for users sharing a device
Short Summary of issue (issue description): Customer is needing assistance with settings for secure log out of the Mobile Work Orders application. Please see details below in the "Recreation Steps" section.
Macro Vertical: Convention Centers
Debug Environment:
Customer DB Location: Hosted
Database: Lvcva_Prod_0373308156_USI
Server: Debug-US,1433
Version: 25.3.20260504
V30 Link: https://supportwebus.ungerboeck.com/Lvcva_Prod_0373308156_USI_V30
User Login: usiadmin / ITRocks2014
Recreation Steps:
Here is the email received from the customer:
We are preparing Zebra ET40 Android tablets for Operations teams to use for mobile work orders across multiple shifts. The tablets are being deployed as corporate-owned, dedicated kiosk devices through Intune, with Chrome restricted to the Momentus web application.
The primary issue is ensuring that each user receives a fully clean and secure session when using a shared device. Users authenticate to Momentus through Entra ID SSO and MFA; however, after a user signs out of Momentus or the tablet is restarted, the next user can be silently signed back in as the prior user without being prompted to authenticate.
Our IT Operations team has tested several Intune and Chrome controls—including Managed Home Screen shared sign-in, clearing local data on user switch, session-only browser cookies, and browser-data cleanup policies. These controls improve device security but do not reliably terminate the prior user’s browser and SSO session in this shared-kiosk scenario. Could Momentus please advise whether there are application-side settings or supported configurations that would address this? Specifically, we would like to understand:
- Whether Momentus can enforce a short server-side idle/inactivity timeout for shared devices, such as 5–15 minutes.
- Whether Momentus can require reauthentication for each new session or disable persistent sessions for designated shared-device users.
- Whether the Momentus logout process can fully invalidate both the Momentus application session and associated SAML/SSO session, so the next user must authenticate.
- Whether Momentus has a documented or recommended approach for shared Android tablet or kiosk deployments.
- Whether there is a Momentus native mobile application or other supported mobile-work-order option that would be better suited to a shared-device model.
We will continue hardening the Chrome kiosk configuration, including restricting access to Momentus only. However, an application-level session control would be the most reliable way to prevent one Ambassador from inadvertently accessing another user’s authenticated session.
Please let us know if this can be reviewed by the appropriate Momentus technical or security resources. We would be happy to schedule a working session with our IT Operations team to walk through the behavior and testing completed.
Observed vs. Expected Results: Unsure - need to figure out where the timeout settings are for angular apps
What does the client want to accomplish: Ensuring each user of MWO receives a fully clean and secure session when using a shared device
Tagging: Cathy Herrick please advise
-
Mike Schepker Jonathan Schmidt - tagging both of you in case you have any advice for this case
-
I don't know about a timeout for Angular apps. I'm not sure if there is one set by default like with some of the other apps (Registration has a 30 minute timeout for example).
Looking at their SSO configuration, their SSO logout URL does not seem correct (see below). That should be the logout URL for their SSO, not their v30 site. If they can provide their SSO logout URL we can attempt to update the SSO config and see if that has any impact with signing out completely in MWO.

Please sign in to leave a comment.
Comments
2 comments
Date Votes