--Revoking user sessions through Entra Admin—

Ian Feldenzer

First Edition

This guide documents the process of revoking sessions in the event of account takeovers. This should be the first thing done in the event of a takeover alert being concluded as a true positive. 

  1. On the Entra Home page, head to the left hand column under “Identity”, then select “users”, then “All Users”.

A screenshot of a computerDescription automatically generated

 

  1. Search the user’s name, then click on it to head to user properties:

A screenshot of a computerDescription automatically generated

 

  1. Once here, select “Revoke Sessions” from the top ribbon. You will then be given one final prompt confirming this, along with the note that the user will need to sign back in. Additionally,  Every device tied to a particular user will get signed out from this method. 
     
    A screenshot of a computerDescription automatically generated

A white background with black textDescription automatically generated