Skip to content
English - Australia
  • There are no suggestions because the search field is empty.

How long does "remember this device" last?

One week; after ticking 'remember this device' the user is not prompted for MFA on that device for 7 days.

After ticking the "remember this device" checkbox at sign-in, the user won't be prompted for MFA on that device for 7 days. After 7 days, MFA is required again on the next sign-in.

The 7-day window balances security (a forgotten or lost device shouldn't bypass MFA indefinitely) with convenience (users on their own machines aren't prompted every single day). The window is shorter than the industry default (30 days is common) because compliance work involves sensitive customer data and the higher-security default is appropriate.

The "remember this device" checkbox should never be ticked on a shared or public computer - it caches the device authorisation for 7 days regardless of who's using the machine. For staff who travel and use multiple devices, the prompt is a useful reminder to be deliberate about which devices they trust.

Related articles