logo
search
Others

Why Disconnect-MgGraph Does Not Clear Microsoft Graph Scopes

Amos GikundaAmos Gikunda Sep 30, 2026 869 views

Question details

The user needs to understand why previously used permissions and scopes persist in Get-MgContext even after disconnecting from Microsoft Graph PowerShell.

Why Disconnect-MgGraph Does Not Clear Microsoft Graph Scopes
Product
Microsoft Graph PowerShell
Device & OS
not provided
Scenario
Managing PowerShell sessions and verifying permission scopes for Microsoft Graph API.
Observed behavior
Get-MgContext continues to display previously used scopes because Disconnect-MgGraph ends the session but does not remove cached consent or granted permissions.
Before you start

Before troubleshooting PowerShell authentication, be aware that disconnecting a session is fundamentally different from revoking application permissions in Microsoft Entra ID.

Solution 1Recommended

Understand Cached Scopes and Seek Expert Support

Disconnect-MgGraph clears the local session context but does not revoke Azure AD cached consent or service principal permissions.

When you run Disconnect-MgGraph, it successfully terminates your local PowerShell session. However, it does not revoke the OAuth delegated permissions or cached tokens that were already granted to the Microsoft Graph Command Line Tools application in your tenant.

Because authentication caching, token expiration, and delegated permissions involve complex Azure AD architecture, this issue is best handled by specialists.

1
Review current context scopes

Run the 'Get-MgContext' command to view the currently active scopes and verify which old permissions are still lingering due to token caching.

2
Revoke permissions in Microsoft Entra

If you need to permanently remove these scopes, navigate to the Microsoft Entra admin center, locate the Enterprise Application for Microsoft Graph PowerShell, and manually revoke the granted permissions.

3
Consult the Microsoft Q&A community

Visit the official Microsoft Q&A PowerShell community at https://learn.microsoft.com/en-us/answers/tags/426/powershell for specialized guidance on Graph authentication and token behavior.

Community Support: The Microsoft 365 business and Exchange Online licensing forums may not provide the detailed PowerShell guidance required for Graph API token issues. The dedicated PowerShell Q&A tag is the best resource.
Free Microsoft Office alternative

Simplify Your Document Workflow with WPS Office

While managing Microsoft Graph PowerShell scripts and Azure AD permissions can be highly technical and complex, handling your daily documents doesn't have to be. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for all your Word, Excel, and PowerPoint needs.

  1. 1. Download the software: Visit the official WPS Office website and click the free download button.
  2. 2. Install the suite: Run the downloaded installer file and follow the quick on-screen instructions.
  3. 3. Start creating: Open WPS Writer, Spreadsheet, or Presentation and enjoy full compatibility with your existing Microsoft documents.
Fully compatible with Microsoft Office formats, including .docx, .xlsx, and .pptx.Lightweight architecture that uses minimal system resources compared to Microsoft 365.Familiar tabbed user interface, ensuring a seamless migration with zero learning curve.Built-in PDF toolkit allows you to easily edit, convert, and merge documents without third-party tools.
microsoft office alternative - wps office

Frequently Asked Questions

How do I force Microsoft Graph PowerShell to ask for login credentials again?

To force a new authentication prompt and clear the local token cache, you can delete the '.graph' folder located in your local user profile directory, or use the 'Connect-MgGraph -ForceRefresh' parameter.

Does Disconnect-MgGraph revoke application permissions in Azure?

No. The Disconnect-MgGraph command only ends your active local PowerShell session. It does not revoke the admin consent or application permissions granted in Microsoft Entra ID. You must remove those manually via the Azure portal.

Why does Get-MgContext show scopes I didn't request in my current session?

Microsoft Graph PowerShell accumulates scopes over time. If you previously connected and granted consent to specific scopes, those permissions are cached in the application's service principal. Get-MgContext displays all cumulatively granted scopes, not just the ones requested in your most recent connection.