What is session revocation?¶
Session revocation invalidates defined continuing authority so that a session can no longer access the cloud service. Its scope matters: ending one session may leave refresh tokens, other devices, applications, API keys and service accounts active.
Record the control and its target¶
Identify the session or token IDs, account, revoking actor/process, time, reason and provider control used. “Sign out everywhere” and a password reset can behave differently between services and applications.
Preserve the pre-revocation session and audit records where urgency permits. Revocation changes the environment and may remove live state, but protecting people or systems may require immediate action.
Test the result¶
Look for the revocation event, subsequent failed use and last successful action. Later activity may use another session or credential rather than prove that revocation failed.
Document intended scope and observed effect. This separates what the responder attempted from what the provider actually invalidated.
The point to remember
Session revocation ends specified authority, not every access route. Preserve its target and verify the result against later events.