At least one Conditional Access policy is configured to enforce non persistent browser session for non-corporate devices
Why This Matters
Non corporate devices such as shared or public computers pose a significant data leakage risk if browser sessions remain persistent. Without a policy enforcing non persistent browser sessions, users can leave active sessions that expose sensitive Microsoft 365 data to the next person using the device. Configuring this control helps ensure that access tokens are discarded when the browser closes, reducing exposure on untrusted endpoints.
What Aether365 Checks
Aether365 verifies that at least one Conditional Access policy is configured to enforce non persistent browser sessions for non corporate devices. This check appears in your Aether365 dashboard under the microsoft-365 checks section.