What are the best practices for session management?

Thanks Dawid

I am not sure about this.
I configured the Session Lifetime and it only works when I refresh the page. However, even if it times out, I can still get the access token to trigger the microservices , it works until I set the access token lifetime to be the same as the session lifetime