Connect on Login
- Last validated: Sep 25, 2026
- 2 minutes to read
- Connect on Login Overview
- Pre-requisites
- Steps to Configure Connect on Login
- Connect on Login on more than one Service Tunnel
- Admin Lock
- Configure Admin Lock
- Time Constraint
Connect on Login Overview
Connect on Login auto-connects end users in your org to a pre-configured Service Tunnel when they log onto their app. The Service Tunnel connection is maintained when the system sleeps and awakens, and even after the system starts. Admins can define the duration of the Connect on Login session, and they can lock an auto-connected Service Tunnel configuration so that end users cannot modify it.
Pre-requisites
- desktop app version 3.17+
Steps to Configure Connect on Login
-
In the Command Center, navigate from Private Access > Service Tunnels, and then select + Add Service Tunnel.
-
In Assignment Settings (of the Service Tunnel configuration), toggle on Connect on Login.
Note: Connect on Login is only evaluated during device registration.
Connect on Login on more than one Service Tunnel
You can enable Connect on Login on several Service Tunnels at once. A user only ever holds one auto-connected tunnel, so when more than one of the tunnels assigned to that user has the setting enabled, the app connects the one whose name comes first alphabetically.
Two things follow from this:
- Name your tunnels with this in mind. If a particular tunnel should be the one users land on, make sure its name sorts ahead of the others that have Connect on Login enabled, or enable the setting on that tunnel alone.
- The user can still switch. Connecting alphabetically decides only the starting tunnel. Users can change to another Service Tunnel afterwards unless you also lock the configuration, as described in Admin Lock.
Admin Lock
Admins can ‘lock’ a Service Tunnel into the auto-connect configuration, meaning that end users cannot disable the configured Service Tunnel from auto-connecting from their devices. End users can still switch to another Service Tunnel, but they will not be able to change the auto-connection setting.
Configure Admin Lock
To lock a Service Tunnel into the auto-connect configuration in Assignment Settings, toggle on Prevent users from choosing a Service Tunnel to Connect on Login.
Time Constraint
Admins can define a time interval for Connect on Login. This time interval is applied at an org-level. When the configured time interval expires, the Service Tunnel is disconnected.
An auto-connected Service Tunnel lasts only as long as the user’s session. The tunnel is disconnected when that session ends, whether the session reaches its maximum length, ends after a period of inactivity, or ends because the user signed out of their device or restarted it. All of these are configured in the Command Center under Settings > Configuration > Advanced. See Control Remote Access Sessions.