Changing a password or enabling OTP does not necessarily sign you out of every device. A service may end its own identity-provider session while an app’s separate cookie or token remains valid. OTP enrollment is a security-factor change, not a reliable substitute for explicitly revoking sessions. To force a fresh sign-in, use the provider’s revoke or sign-out-all control and, where needed, the app’s own session controls.
Why a session can survive a password change
A signed-in app can rely on several separate credentials: a session held by an identity provider, an app’s own session cookie, and access or refresh tokens. Those credentials may be issued and expired independently. Microsoft explains that browser apps commonly issue their own session token, which Microsoft Entra ID cannot directly revoke; Auth0 Support likewise describes an application session that can remain after its Auth0 server session expires.
That is why changing a password may sign you out of some services, leave other apps open, or prompt for a new sign-in only when a token expires. The result depends on the provider’s revocation behavior, the app’s session design, and whether the app checks back with the provider. A password change alone is not a dependable global logout.
What enabling OTP does to sessions
OTP enrollment adds an authenticator factor for future authentication or challenges; it does not, by itself, establish that existing sessions have been terminated. Auth0’s documentation describes enrolling and challenging OTP authenticators, while its session-revocation API documents a separate operation to revoke a session and associated refresh tokens. The reviewed documentation does not establish a universal rule that enrolling OTP logs out existing devices.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Standard OATH compliant TOTP token (time based)
- 6-digit OTP code with countdown time bar
- Zero footprint: no need for the end user to install any software
- Secure, sturdy, and long-life hardware design
- Easy to use - Portable key chain design. These tokens will only work with Symantec VIP Access. These tokens will not work for any other Multi-Factor Authentication services, besides Symantec VIP Access.
An already-signed-in app may therefore remain accessible until its session expires, the app or provider revokes it, or a policy requires reauthentication. If the goal is to make every device sign in again and satisfy MFA, explicitly revoke sessions and tokens, then confirm that each relevant app will require fresh authentication and apply its MFA policy.
How the documented provider controls differ
| Provider | Documented behavior | Important limit |
|---|---|---|
| Microsoft Entra ID | The “Revoke sessions” control blocks future use of Entra tokens. Microsoft says Entra-issued access tokens last one hour by default. | Apps can issue their own session tokens, which Entra cannot directly revoke. Access may continue until token expiry, and app-session behavior depends on the app’s expiry, synchronization, or revocation handling. The one-hour default is not a guarantee that every app will be signed out within an hour. Microsoft’s emergency access-revocation guidance also says app provisioning typically runs automatically every 20–40 minutes; that is a provisioning interval, not a universal session-revocation delay. |
| Okta | During a password reset, an admin or end user can select an option to sign the user out of Okta sessions on all devices and browsers. Admins can also use “Clear User Sessions” and select “Clear Sessions & Revoke Tokens.” | The documented effect is on Okta sessions and tokens. Do not assume that every downstream app’s locally managed session ends too. See Okta’s session-revocation guidance. |
| Auth0 | Auth0’s session API provides a per-session revocation operation that also revokes associated refresh tokens. Auth0 Support says an app’s local session can survive expiration of the Auth0 server session. | Revoking the Auth0 session does not necessarily invalidate a separate app cookie. The password-reset behavior is described in Auth0 Support’s password-reset article; the revocation operation is documented in the Auth0 session API. |
How to force existing sessions to end
- Use the identity provider’s explicit revocation control. Depending on the provider, this may be called “Revoke sessions,” “Clear Sessions & Revoke Tokens,” or sign out of all devices. For Auth0, use its session-revocation API for the relevant session.
- Invalidate app-owned sessions too. If the app maintains its own cookie, server-side session, or tokens, use the app’s logout or session-revocation mechanism. Entra’s documentation states that an application must revoke access based on its own authorization policies to revoke an app-issued session token.
- Check what happens at the next sign-in. Revocation and OTP enrollment do not alone prove that every app will require OTP. Confirm the app’s reauthentication and MFA policy, especially where apps use their own sessions.
- Verify the outcome on the services that matter. Test or check each relevant app rather than assuming that a provider-level sign-out has cleared every local session.
If you suspect the account is compromised
Use the identity provider’s emergency revocation flow, block further sign-ins if warranted, and revoke sessions or refresh tokens. Also invalidate sessions owned by relying apps. Microsoft warns that revocation can be delayed by token and app behavior and advises applications to revoke their own sessions and stop accepting tokens as appropriate. Changing the password alone should not be treated as immediate, universal sign-out.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
What to check before relying on a logout
- Is the session owned by the identity provider, the app, or both?
- Does the app use access tokens, refresh tokens, a local cookie, or a combination?
- Which specific control revokes each credential, and does the app enforce that revocation?
- Will a fresh sign-in trigger OTP/MFA under the app’s current policy?
- Does the control force reauthentication, or only prevent future token renewal while existing credentials expire?
The documented examples here cover Microsoft Entra ID, Okta, and Auth0; other providers and app configurations may behave differently. Tenant settings, app protocols, product versions, and application-side session handling all affect the outcome.
Quick Recap
Best Value
- Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
- FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
- Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
- Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
- IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.
Rank #4
- OTP token that provides secure remote access with strong authentication
- Easy to use and easy to carry
- Expected battery life is approximately 7 years
Rank #3
- Protect accounts with USB-A & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
- FIDO2 Level 2 certified Security Key. TAA compliant and supports Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Works with Chrome, Safari & Edge across major OS.
- Plug & play USB-A Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
- Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication and identity protection.
- IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise and daily use.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

