Sign a user out of everywhere
Revoking sessions ends access on every device within seconds. It is the action that stops an intrusion already in progress.
Revoking somebody’s sessions invalidates what keeps them signed in, so every device has to sign in again. The instruction is applied immediately.
A session already open can survive for up to about an hour on services that do not re-check continuously. Revocation is the right action and it is not instant everywhere, which is why the password matters too.
Use it after a password reset, when a device is lost, or the moment an account is suspected of being compromised.
Before you begin
Warn the person if they are at their desk. They will be signed out of everything mid-task and will lose unsaved work in web applications.
Have a plan for what they do next. Somebody signed out of everything and given no new password is stuck.
Ask Avvi
- Open chat and check the client.
- Ask for their sessions to be revoked, naming them. For example: revoke sessions for jane@example.com.
- Read the confirmation and check the name.
- Confirm.
Avvi reports the revocation. Access ends as each service re-checks, which is immediate on some and up to about an hour on others.
Good to know
An MFA reset revokes sessions only when it actually removed a method. An account whose only method cannot be removed remotely reports success and revokes nothing, so a separate request is worth making every time.
A password reset asks whether to sign the person out. In a compromise the answer is always yes, and asking for revocation separately is still the way to be certain.
Verify it worked
Wait a few minutes, then ask the person to try a signed-in application. Checking immediately can show access that has not yet been re-evaluated.
For a suspected compromise, check afterwards that no inbox rules or forwarding were left behind. Ending the session does not remove what was set up during it.
If something doesn’t look right
If the person is not signed out, allow several minutes before repeating. Some services re-check on their own schedule.
If they sign back in immediately and should not be able to, the password has not been changed. Revocation alone leaves a known password working.
If access continues on one device only, that device may be using a stored token for a service that refreshes separately. Reset the password as well.
To escalate, open a support conversation from the Help drawer with the client, the person, and what still has access.
FAQ
Q: Does this change their password?
A: No. Change it separately if the password may be known.
Q: How fast is it?
A: The instruction is immediate. An open session can persist for up to about an hour on some services.
Q: Do I need this after resetting multi-factor?
A: Yes. That reset only revokes sessions when it actually removed a method.