Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To contain a malicious Microsoft 365 app, disable its enterprise application in Microsoft Entra, then revoke sign-in sessions for every affected user. These are separate actions: disabling the app blocks it from obtaining new tokens, while revoking a user’s sessions invalidates that user’s refresh tokens and browser session cookies. Neither action necessarily ends every application session immediately.

Before you change anything, identify the app and affected users

Find the suspicious enterprise application in Microsoft Entra and record its display name, identifiers, publisher, permissions, consent details, and the users who authorized or used it. Where your incident process requires it, preserve relevant evidence before changing the app’s state.

Search audit records for the affected users, the period when the app had access, and the permissions involved. Microsoft’s app consent grant investigation playbook and guidance on illicit consent grants describe the records and investigation scope to review. The necessary mailbox and admin or user activity auditing must have been enabled before the suspected attack; searchable retention also depends on your subscription. An empty search does not establish that no access occurred if logging was unavailable or the records were not retained.

Disable the malicious app to stop further access

In the Microsoft Entra admin center, locate the identified enterprise application and use Microsoft’s Disable an application procedure. Disabling is the primary app-level containment action: Microsoft says a disabled app cannot obtain new tokens to access data, and other users cannot sign in to it or grant it consent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Prefer disabling over deleting during initial containment. Microsoft cautions that deleting an app alone may not prevent it from returning if another user grants consent later. The compromised and malicious applications playbook also describes disabling sign-ins while responders assess impact and decide whether further steps, such as deletion or key rolling, are appropriate.

Revoke sessions for each affected user

Use the Microsoft Entra admin center’s Revoke sessions action for each affected user, or use Microsoft Graph PowerShell. The following command pattern is documented in Microsoft’s compromised email account response guidance:

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Connect-MgGraph -Scopes User.RevokeSessions.All
Revoke-MgUserSignInSession -UserId <UPN>

Replace <UPN> with the affected user’s sign-in name. The signed-in administrator needs the User.RevokeSessions.All scope. Microsoft Graph’s revokeSignInSessions API documentation explains that the operation resets the user’s signInSessionsValidFromDateTime, invalidating refresh tokens and browser session cookies so applications must obtain a new refresh token through sign-in.

This operation does not revoke sign-in sessions for external users, who authenticate through their home tenant. Contact the external user’s home organization to coordinate that response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Remove other ways the attacker could regain access

Session revocation does not replace a review of account persistence. For affected users:

  • Review registered MFA devices and authentication methods; remove anything unrecognized or unauthorized.
  • Review user-consented applications and remove or revoke grants that should not remain.
  • Check that the malicious enterprise app remains disabled while the investigation continues.

Microsoft includes these account checks in its compromised email account response guidance.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Know what revocation does—and does not—end

Entra cannot directly revoke a session token issued by a downstream application. A user may have both an Entra session and a separate application-issued session; the application controls its own session cookie and may not send the user back to Entra until that session expires or the application revokes it. Microsoft explains this distinction in its emergency access guidance.

Microsoft says Entra access tokens are typically valid for one hour. Revoking a refresh token prevents its renewal, but an already-issued access token may continue to work until it expires unless the service evaluates revocation sooner. Continuous Access Evaluation can improve invalidation timing in supported scenarios, but it does not guarantee immediate termination for every app or session.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Action What it affects Important limit
Disable the enterprise app Prevents that app from obtaining new tokens and blocks additional tenant sign-ins or consent. Does not itself revoke every affected user’s existing session.
Revoke a user’s sessions Invalidates that user’s refresh tokens and browser session cookies. Does not directly revoke an application-issued session token or an external user’s home-tenant session.
Revoke an app-owned session Ends a session controlled by the downstream application. Must be handled by that application; Entra cannot directly revoke its session token.
Delete the app Removes the app object. Deletion alone may allow it to return after a later consent grant, so Microsoft recommends disabling for containment.

Reduce the risk of another consent attack

Review the organization’s user-consent controls in the Entra enterprise-app consent and permissions settings. Microsoft recommends allowing user consent only for applications from verified publishers. Its user consent configuration guidance covers these controls. You can also consider an admin consent workflow and risk-based step-up consent so risky requests are routed to an administrator when user consent is enabled.

For organizations with the necessary licensing, Microsoft identifies Defender for Cloud Apps OAuth application auditing and the Consent Insights workbook in Azure Monitor as optional ways to monitor consent-related activity. They are monitoring capabilities, not prerequisites for disabling an app or revoking user sessions.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.