What is the difference between revoking a user session and revoking user MFA session in Entra ID

Vuy Si 26 Reputation points
2024-08-05T16:15:02.47+00:00

Hi,

I'm trying to understand the difference between revoke sessions option in a user overview page and revoke mfa authentication sessions option under authentication methods.

From testing, revoke sessions will sign a user out from all devices and require them to sign back in to resume access.

I assume revoke mfa authentication sessions will require them to provide mfa the next time they try to sign in to an app that needs mfa even if they have previously provided it.

Is this correct?

User's image

User's image

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,262 questions
{count} vote

Accepted answer
  1. Andy David - MVP 149.7K Reputation points MVP
    2024-08-05T16:28:48.1066667+00:00

    Correct. Revoking MFA sessions will simply require them to do MFA again on apps that require it

    https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userdevicesettings

    User's image

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Matteo Giordani 0 Reputation points
    2024-11-21T08:36:24.7033333+00:00

    Hi,
    this clarification was very helpful.
    I have a question, I need to revoke MFA session for all tenant users massively, I tried searching but I can't find a powershell command to be able to do it in one go for all users, to avoid having to do it by hand one by one, can someone help me to understand what powershell command I should use?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.