Skip to content
Skip to main content
Cloud Services Technical Explainer

Can a cloud session remain active after a password changes?

Yes. A password change alters one authentication route. Existing browser sessions, application sessions and tokens are separate credentials, and some may continue until the relevant provider or application rejects, expires or revokes them.

One change can produce several outcomes

Dave changes his Northstar password at 13:00. A new password login using the old value fails at 13:04, but an existing SharePoint browser session opens a file at 13:07. A sync client stops only when its next token request is rejected. A third-party case application retains its own session until that application ends it.

Build a credential-by-credential timeline

Record Question it answers
Password change, reset or recovery event Who or what changed the password, when and through which route?
New sign-in result Did the provider accept the old or new password for fresh authentication?
Browser/application session event Did a separately issued session remain valid?
Refresh-token or non-interactive sign-in Did the identity platform renew continuing authority?
Resource event What did the surviving route actually access or change?
Revocation, expiry or sign-out Which credential ended, under whose policy and when?

The cloud session, access token and refresh token explain the separate mechanisms. Do not compress them into “the account stayed logged in”.

Microsoft revocation behaviour - checked 2 September 2026

Microsoft documents different password-change and reset effects for password-based, non-password-based and confidential-client refresh credentials. It also explains that an application controls a session cookie it issued; Microsoft Entra cannot directly revoke every application session.

Preserve before intervention where circumstances allow

Password resets, session revocation and “sign out everywhere” can protect an account but also create events and close evidence-bearing routes. Record the pre-change sessions, applications and identifiers where urgency permits, then document every containment action and observed effect.

The point to remember

A password change affects a password route, not automatically every credential already issued. Follow each session, token and application to its own expiry, rejection or revocation event.

Reference: CLD-030Cloud Services