Controls session lifetime and how many sessions are kept for each user.
How many hours each active session is extended after activity.
Only the latest sessions are kept; older ones are closed automatically.
Controls failed login monitoring and risk thresholds.
Time window in minutes for counting failed login attempts.
Failed attempts count required to mark login as medium risk.
Failed attempts count required to mark login as high risk.
Stores risk level and risk flags in Security Activity.
Controls device tracking and location collection behavior.
Registers browser/device identity and links sessions to devices.
Allows protected pages to request browser location for the current session.
When enabled, untrusted devices can be blocked until approved.