Mass session revoke across the whole user base

Nana Poku 345 Reputation points
2026-03-13T11:18:48.0033333+00:00

We are planning to perform a mass session revocation across the entire user base following the recent threat intelligence briefings regarding cyber activity linked to the Iran conflict.

Microsoft Security | Microsoft Graph
0 comments No comments

1 answer

Sort by: Newest
  1. AI answer

    2026-03-13T11:19:08.2666667+00:00

    A mass session revocation can be approached in layers to invalidate user access tokens, refresh tokens, and device/app access as broadly as possible.

    1. Revoke Microsoft 365 / SharePoint Online sessions per user (PowerShell)
      • Use the Revoke-SPOUserSession cmdlet to invalidate Office 365 sessions for users across all devices.
      • Prerequisites:
        • Must be a Global Administrator.
        • Must have a valid SharePoint Online connection context using Connect-SPOService.
      • Example for a single user:
             Connect-SPOService -Url https://<tenant>-admin.sharepoint.com
             
             Revoke-SPOUserSession -User ******@contoso.com -Confirm:$false
        
      • When run, this signs the user out of browser, desktop, and mobile applications accessing Office 365 resources across all devices. It does not apply to guest users.
      • For a mass operation, iterate over all users in the tenant and call Revoke-SPOUserSession for each. Expect responses such as:
        • We successfully signed out <user> from all devices.
        • It can take up to an hour to sign out <user> from all devices.
    2. Revoke Microsoft Entra ID tokens and sessions (Graph / Entra)
      • Use Microsoft Graph’s sign-in/session revocation APIs (for example, revokeSignInSessions) to invalidate refresh tokens and active sessions so that future token refreshes fail.
      • This complements Revoke-SPOUserSession by covering non-SharePoint/Office 365 apps integrated with Microsoft Entra ID.
      • Be aware that revocation is not always instantaneous; access tokens are typically valid for up to 1 hour by default. During that period, existing access tokens may still work until they expire.
    3. Use Continuous Access Evaluation (CAE) where possible
      • Enable and use Continuous Access Evaluation (CAE) in Microsoft Entra ID for CAE-capable apps.
      • CAE allows admins to revoke session and access tokens in near real time for supported applications, reducing the window in which compromised tokens remain usable.
    4. Device and app data protection (Intune)
      • For managed devices, use Microsoft Intune to wipe or retire devices or perform a selective wipe of corporate data from managed apps.
      • This helps remove sensitive data that may already be cached locally on devices. Note that the device must be online for the wipe to complete, and wiped data cannot be recovered.
    5. Browser/app session considerations
      • Some applications maintain their own local session caches or cookies that are not fully cleared by token revocation alone.
      • In such cases, combine:
        • RP-initiated logout via OpenID Connect (front-channel logout to notify relying parties),
        • Graph-based session revocation,
        • And user communication instructing users to close and reopen browsers or sign out of specific apps.
    6. Best-practice posture for threat-driven mass revocation
      • Combine:
        • Entra ID token/session revocation,
        • Revoke-SPOUserSession for Office 365 workloads,
        • CAE for near real-time enforcement,
        • Intune device/app wipes where risk is high,
        • And monitoring of sign-in activity for anomalous behavior.
      • Avoid over-reducing access token lifetimes solely for this event, as it can degrade user experience and increase load, while not providing true real-time revocation compared to CAE and explicit session revocation.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.