A session is usually handled by creating a unique identifier as a cookie on the client machine. This is usually a session cookie, so you cannot easily reach it. When you visit a site that uses sessions, it searches for this cookie. If he does not find it, he creates a new one, creating a new session.
One way to set the expiration time is in web.config, you can also set it in IIS by going to the properties of your website → tab “Home” → button “Configuration” → tab “Settings” → “timeout” session. "
You will not be able to access elses session data.
source share