Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To revoke Microsoft 365 sign-in sessions, connect to Microsoft Graph PowerShell with the User.RevokeSessions.All scope and run Revoke-MgUserSignInSession -UserId <UPN>. Treat this as one containment step, not a guarantee that every active connection stops immediately: first block the compromised account if feasible, then revoke sessions, reset credentials in the correct identity source, remove attacker persistence, and investigate what happened.
Contain the account before investigating
Microsoft recommends disabling a compromised account during the investigation when possible. Blocking the account limits new access while you assess the incident; if you cannot disable it, reset its password. Do not send a replacement password to the mailbox that may be compromised.
- Disable access. For a cloud-only account, disable the user in Microsoft Entra. For a synchronized account, disable the user in on-premises Active Directory as well as taking any needed Entra action; Microsoft’s emergency guidance specifically calls for disabling the AD account.
- Reset the credential at its source. For synchronized or federated identities, make the password change in the on-premises identity environment. Microsoft’s compromised-mailbox guidance calls for resetting a synchronized AD password twice to mitigate pass-the-hash risk, particularly where password replication may be delayed. Coordinate with the on-premises identity administrator for federated users.
- Account for app passwords. Microsoft says app passwords are not automatically revoked by a password reset, so update them separately where they are in use.
Revoke Microsoft 365 sign-in sessions
Use Microsoft Graph PowerShell
Use the Microsoft Graph Authentication and Users.Actions modules. Connect with the least-privileged scope Microsoft lists for this operation, then target the affected user by user principal name:
Connect-MgGraph -Scopes User.RevokeSessions.All
Revoke-MgUserSignInSession -UserId <UPN>
Replace <UPN> with the affected user’s sign-in name, such as alex@example.com. The required Microsoft Graph permission for a work or school account is User.RevokeSessions.All, listed as the least-privileged delegated or application permission. The equivalent Microsoft Graph v1.0 operation is POST /users/{id | userPrincipalName}/revokeSignInSessions.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What the command revokes—and what it does not
The operation invalidates refresh tokens issued to applications and browser session cookies by updating the user’s signInSessionsValidFromDateTime. Microsoft warns that revocation may take a few minutes, so do not treat a successful command response as proof that every existing connection has already ended.
- An access token already issued to an application may remain usable until it expires. Microsoft Entra’s emergency guidance says access tokens last one hour by default; token behavior can depend on the application and configuration.
- An application that issues or maintains its own session may require a separate session revocation or user deprovisioning action.
- The operation does not revoke sessions belonging to external users, who authenticate through their home tenant.
In other words, Microsoft Graph session revocation addresses the user’s Microsoft sign-in sessions; it is not a universal kill switch for every application session or token-backed connection.
Rank #2
- PHISHING-RESISTANT 2FA: Cryptographically binds to real domains, making phishing attacks impossible unlike SMS codes or authenticator apps.
- 3-SIDE CAPACITIVE TOUCH: Tap the end, left, or right side to authenticate, so it works in any orientation or crowded USB port.
- MULTI-COLOR LED INDICATOR: Blue means ready, blinking blue means tap now, green means success, and red means error for instant status feedback.
- IP68 WATERPROOF & BATTERY-FREE: Crush-resistant one-piece construction survives daily carry on a keychain or in a bag for years without any batteries.
- UNIVERSAL COMPATIBILITY: Works with Google, Microsoft, Apple, GitHub, AWS, and any FIDO2 / U2F / WebAuthn service, storing up to 100 passkeys.
Remove attacker persistence
After access is contained, inspect the account and mailbox for changes an attacker could use to return or continue operating. Preserve relevant evidence before removing suspicious items.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Authentication methods and devices: review registered MFA methods and devices; remove entries the user and administrators do not recognize.
- Consented applications: review user-consented apps and revoke access for applications that should not be allowed.
- Administrative access: inspect the user’s Entra roles and remove unauthorized role assignments.
- Mailbox forwarding: check mailbox forwarding settings for unfamiliar SMTP destinations.
- Inbox rules: review all rules, including hidden rules, for unexpected forwarding or redirection. In Exchange Online, Microsoft’s inspection example is
Get-InboxRule -Mailbox <Identity> -IncludeHidden. Examine rules withRedirectTo,ForwardTo, orForwardAsAttachmentTovalues and remove suspicious rules after preserving what is needed for investigation.
Investigate the compromise and verify recovery
Build a timeline that starts just before the suspected activity and continues through remediation. A forwarding rule or unusual message is an investigation signal, not proof of account takeover on its own.
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
- Review Entra sign-in logs and risk reports for unfamiliar IP addresses, locations, times, and successful or failed sign-ins.
- Review Defender audit logs over the same period, beginning before the suspicious activity and extending through remediation.
- Inspect messages sent during the suspicious period. Use Message Trace to verify what was sent and identify potential recipients or impact.
- Check for other reported compromise indicators, including missing or deleted mail, suspicious sent or deleted items, unexpected password changes or lockouts, and altered signatures.
- If Microsoft 365 blocked the user from sending spam, remove the user from Restricted entities only after investigation and recovery work are complete.
- If you disabled the account for investigation, reset its password and re-enable it after the investigation is complete.
Choose the response for the identity source
| Account type | Containment and credential action | Session-revocation boundary |
|---|---|---|
| Cloud-only Entra account | Disable the account during investigation when feasible; an administrator can select Revoke sessions in the Entra admin center or use Microsoft Graph PowerShell. Reset the cloud credential if needed. | Microsoft session revocation can invalidate refresh tokens and browser cookies, subject to the delay and token/application behavior described above. |
| Synchronized or federated identity | Disable the on-premises AD account and reset its password in the on-premises environment. Microsoft’s emergency guidance recommends two resets for synchronized accounts; coordinate federated password changes with the on-premises identity administrator. | Use Microsoft session revocation as part of containment, but handle the authoritative on-premises identity and any application-owned sessions separately. |
| External user | Coordinate with the user’s home-tenant administrator to contain that identity. | This operation does not revoke sessions in the external user’s home tenant. |
Microsoft guidance and scope
The procedure above reflects Microsoft Learn’s Respond to a compromised email account in Microsoft 365 guidance, updated July 17, 2026; the Microsoft Graph v1.0 user: revokeSignInSessions reference; and Entra emergency revocation guidance, updated June 19, 2026. Portal labels, permissions, and token behavior can change, so confirm the current Microsoft documentation for your tenant and deployment before running a response procedure.
Quick Recap
Best Value
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Rank #4
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

