Microsoft Security | Microsoft Graph
An API that connects multiple Microsoft services, enabling data access and automation across platforms
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
We are planning to perform a mass session revocation across the entire user base following the recent threat intelligence briefings regarding cyber activity linked to the Iran conflict.
An API that connects multiple Microsoft services, enabling data access and automation across platforms
AI answer
A mass session revocation can be approached in layers to invalidate user access tokens, refresh tokens, and device/app access as broadly as possible.
Revoke-SPOUserSession cmdlet to invalidate Office 365 sessions for users across all devices.Connect-SPOService. Connect-SPOService -Url https://<tenant>-admin.sharepoint.com
Revoke-SPOUserSession -User ******@contoso.com -Confirm:$false
Revoke-SPOUserSession for each. Expect responses such as:
We successfully signed out <user> from all devices.It can take up to an hour to sign out <user> from all devices.revokeSignInSessions) to invalidate refresh tokens and active sessions so that future token refreshes fail.Revoke-SPOUserSession by covering non-SharePoint/Office 365 apps integrated with Microsoft Entra ID.Revoke-SPOUserSession for Office 365 workloads,References: