Session.Timeout controls how many minutes a Classic ASP session may remain inactive before IIS expires it. Activity on the application refreshes the inactivity timer.
Session.Timeout = 10This example sets the timeout to 10 minutes for the current session. Choose a value that balances usability with the sensitivity of the application.
Response.Write "Your session will time out after " & _
Session.Timeout & " minutes"IIS also has an application-level ASP timeout setting. Microsoft documents the default Classic ASP session timeout as 20 minutes unless configuration changes it.
For authenticated applications, timeout is only one part of session security. Use HTTPS, authorization checks on every protected page, and a deliberate logout flow.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.