Skip to main content

New Action: Revoke Sessions

We're gradually rolling out Revoke Sessions - a new response action joining the existing Endpoint Isolation and User Suspension options. Revoke Sessions is a lighter-touch countermeasure that can be executed without significantly disrupting business activities - the user simply needs to log back in.

  • What it does - Revokes all active session tokens for the affected user, immediately logging them out of all devices and requiring them to re-authenticate.

  • How to use it - Revoke sessions is available from the Action Center within Incidents.

  • Approval settings - By default, our MDR analysts are pre-approved to take this action. If you'd prefer our team to require approval first, you can change this under: Security Controls β†’ MDR β†’ MDR Services Configuration β†’ Change to "Approval Required".

* Full user session revocation may take up to an hour for Microsoft 365 tenants due to Microsoft's architecture constraints.

Did this answer your question?