Assume that you deploy AD FS for single sign-on (SSO) by using Windows Server 2016 in Exchange Server 2016 environment. Then you set the value of ActivityBasedAuthenticationTimeoutInterval to less than 4 hours for device registration for users. When the time out value is reached, the Outlook on the web (formerly Outlook Web App) may sign out, and then enters an authentication loop. In this situation, users can't sign in to the Outlook on the web.
Set-OrganizationConfig -ActivityBasedAuthenticationTimeoutInterval 05:00:00
This example specifies the time span for signing out to 5 hours.
Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.