Skip to content
Skip to main content
Cloud Services Technical Explainer

Could a cloud session continue after the user closes the browser?

Yes. Closing a browser window ends the visible interface, but it does not necessarily end the provider-side cloud session or remove the cookie or token that can resume it. A later request can therefore use continuing authority without a fresh password or MFA event.

Closure, sign-out, expiry and revocation differ

At 17:10, Dave closes Edge after using Microsoft 365. The browser profile retains application cookie CK-81; the provider still recognises session SES-L41. At 18:02, Edge is reopened and SharePoint accepts request REQ-9902 under the same session without recording a new interactive sign-in.

Closing the browser may leave a persistent cookie in the profile. Reopening the service can restore access without another password or MFA event. Extensions, sync components and connected applications may also continue background activity.

Signing out normally asks the service to end a session, but behaviour varies. Expiry happens under provider rules, while session revocation deliberately invalidates defined authority.

A provider can terminate the server session while old local cookies remain. The cookie then evidences earlier account use but no longer grants working access.

Later activity may use continuing authority

Look for the original authentication, session ID, refresh events, later access, and sign-out or revocation record. Another person using the same browser profile may reopen the remembered session. Compare REQ-9902 with Edge history and profile artefacts, device-use evidence, and the provider's sign-out or revocation event.

The account holder can therefore truthfully report closing the browser while the service remained technically accessible. That fact alone does not attribute later events.

Microsoft Entra and application sessions - checked 3 September 2026

Microsoft explains that browser authentication commonly creates one session token for Microsoft Entra and another for the application. The application controls its own session under its authorisation policies, and Entra cannot directly revoke a session token issued by that application. Product-specific revocation behaviour must therefore be checked at both layers.

The point to remember

Browser closure is not a security event. Distinguish it from sign-out, session expiry and provider-side revocation when explaining continuing access.

Reference: CLD-109Cloud Services