Session timeout in Classic ASP

Session.Timeout controls how many minutes a Classic ASP session may remain inactive before IIS expires it. Activity on the application refreshes the inactivity timer.

Set the timeout for the current session

Session.Timeout = 10

This example sets the timeout to 10 minutes for the current session. Choose a value that balances usability with the sensitivity of the application.

Display the timeout

Response.Write "Your session will time out after " & _
  Session.Timeout & " minutes"

IIS also has an application-level ASP timeout setting. Microsoft documents the default Classic ASP session timeout as 20 minutes unless configuration changes it.

For authenticated applications, timeout is only one part of session security. Use HTTPS, authorization checks on every protected page, and a deliberate logout flow.


ASP Home






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer