What is the difference between revoking a user session and revoking user MFA session in Entra ID

Vuy Si 31 Reputation points
2024-08-05T16:15:02.47+00:00

Hi,

I'm trying to understand the difference between revoke sessions option in a user overview page and revoke mfa authentication sessions option under authentication methods.

From testing, revoke sessions will sign a user out from all devices and require them to sign back in to resume access.

I assume revoke mfa authentication sessions will require them to provide mfa the next time they try to sign in to an app that needs mfa even if they have previously provided it.

Is this correct?

User's image

User's image

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2024-08-05T16:28:48.1066667+00:00

    Correct. Revoking MFA sessions will simply require them to do MFA again on apps that require it

    https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-userdevicesettings

    User's image

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Matteo Giordani 0 Reputation points
    2024-11-21T08:36:24.7033333+00:00

    Hi,
    this clarification was very helpful.
    I have a question, I need to revoke MFA session for all tenant users massively, I tried searching but I can't find a powershell command to be able to do it in one go for all users, to avoid having to do it by hand one by one, can someone help me to understand what powershell command I should use?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.