Hello Jeff,
Good question. I would assume you can, but not positive. I have asked our systems engineering group about the Thin Client (TC) timeout and will post an update if that option exists.
I have learned more on the elusive 802.1x Re-Authentications. It turns out the developers have implemented " Sticky MAC" on the LAN ports to keep devices logged in and never time out. My hope is they will revisit and add a command option to force re-authentication within a range of 1 to 24 hours.
As long as the device successfully authenticates they should remain connected, until either the port is disconnected, a user forces a logout, or the IP lease time expires in DHCP. Of course, if the devices have a static IP address you can not use DHCP as a means of forcing a re-authentication by trimming down the lease time. This is why Fortinet engineering should add additional functionality, so we meet proper security requirements and do not get flagged on audits! :)
Thanks,
George