A cloud-based identity and access management service for securing user authentication and resource access
Hello Aditya Pande
The current behavior is expected based on the Conditional Access policy configuration.
The policy is configured with Sign-in risk = High, Consequently, the policy will only take effect if a high-risk sign-in is detected. The policy and accompanying session controls won't be activated for regular sign-ins.
Settings like:Sign-in frequency, Periodic reauthentication and Persistent browser session do not work independently and only apply after the Conditional Access policy conditions are met.
Please either temporarily remove the risk criterion or establish a different test policy without the "Sign-in risk = High" condition in order to test the session controls.
Furthermore, confirm the impacted sign-ins under: Conditional Access tab under Sign-in Logs
This will verify whether the policy was assessed and implemented during the user session.
Let me know if any further queries - feel free to reach out!