Should I revoke linked devices or sessions?¶
Revoking linked devices or sessions can protect an account, but it can also destroy useful access and evidence.
Why this matters¶
The dangerous assumption is that removing every unknown session is always the safest first step. Revocation may alert another user, terminate a live evidential opportunity and erase session context from the visible account.
What to record and do¶
Before revoking anything, record each visible device, session name, location, IP address, browser, last-active time and provider identifier.
Capture the whole session-management page before selecting an item.
Consider the actual risk. Is there ongoing fraud, victim harm, remote deletion or active unauthorised access?
Where possible, preserve provider records and obtain specialist advice before taking action.
A narrower response may be available, such as revoking one clearly risky session rather than all access.
Do not assume that an unfamiliar device is malicious. It may be an old phone, work computer, shared device, VPN endpoint or provider label.
If revocation is justified, record which session was selected, the time, the reason and every visible result.
Capture any warning, confirmation, alert or change to the account’s device list.
Record whether the session is linked to a mobile app, browser, hardware token, delegated administrator or third-party integration. Revoking one entry may affect more than the device label suggests and may remove access from a legitimate user.
Do not revoke every session merely because the labels are unfamiliar; preserve and assess them first.
Operational takeaway¶
Revoke sessions only after preserving their identifiers and assessing the risk, because the action may destroy useful context and alert the remote user.