Should I revoke linked devices or sessions?¶
Revoke only when protecting the account from a defined risk outweighs loss of session evidence and possible notification to the remote user.
Preserve entries before removal¶
Record device, session, application, browser, location, IP address, provider ID and activity times. Capture the complete management page and identify current, trusted or managed labels.
An unfamiliar label may describe an old, shared or VPN-connected device rather than hostile access. A session may also represent a token, delegate or integration affecting more than one device.
Match revocation to the threat¶
Ongoing fraud, deletion or unauthorised activity may justify urgent containment. Prefer one clearly risky entry over indiscriminate removal where possible.
Record selection, authority, time, reason, warnings, confirmation and device-list changes. Provider records and specialist advice should be preserved first where the operational window allows.
Key takeaway
Preserve session evidence and assess each entry before revocation, then use the narrowest control that addresses the actual risk.