For SAML logins, we have a policy (SAMLOfflineSigninTimeLimit) that enforces an online flow every X hours. This policy however does not take effect on Google accounts.
FR: Add GAIAOfflineSigninTimeLimit to set the same kind of limit for forcing online re-auth for GAIA accounts. This is required by customers who have second factor flows and who consider re-auth gated only by password to be less secure given the general setup of their accounts with 2FA.
http://dev.chromium.org/administrators/policy-list-3#SAMLOfflineSigninTimeLimit
Comment 1 by atwilson@chromium.org
, Feb 14 2017Owner: dskaram@chromium.org