Why Disconnect-MgGraph Does Not Clear Microsoft Graph Scopes
Question details
The user needs to understand why previously used permissions and scopes persist in Get-MgContext even after disconnecting from Microsoft Graph PowerShell.

- Product
- Microsoft Graph PowerShell
- Device & OS
- not provided
- Scenario
- Managing PowerShell sessions and verifying permission scopes for Microsoft Graph API.
- Observed behavior
- Get-MgContext continues to display previously used scopes because Disconnect-MgGraph ends the session but does not remove cached consent or granted permissions.
Before troubleshooting PowerShell authentication, be aware that disconnecting a session is fundamentally different from revoking application permissions in Microsoft Entra ID.
Understand Cached Scopes and Seek Expert Support
Disconnect-MgGraph clears the local session context but does not revoke Azure AD cached consent or service principal permissions.
When you run Disconnect-MgGraph, it successfully terminates your local PowerShell session. However, it does not revoke the OAuth delegated permissions or cached tokens that were already granted to the Microsoft Graph Command Line Tools application in your tenant.
Because authentication caching, token expiration, and delegated permissions involve complex Azure AD architecture, this issue is best handled by specialists.
Run the 'Get-MgContext' command to view the currently active scopes and verify which old permissions are still lingering due to token caching.
If you need to permanently remove these scopes, navigate to the Microsoft Entra admin center, locate the Enterprise Application for Microsoft Graph PowerShell, and manually revoke the granted permissions.
Visit the official Microsoft Q&A PowerShell community at https://learn.microsoft.com/en-us/answers/tags/426/powershell for specialized guidance on Graph authentication and token behavior.
Simplify Your Document Workflow with WPS Office
While managing Microsoft Graph PowerShell scripts and Azure AD permissions can be highly technical and complex, handling your daily documents doesn't have to be. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for all your Word, Excel, and PowerPoint needs.
- 1. Download the software: Visit the official WPS Office website and click the free download button.
- 2. Install the suite: Run the downloaded installer file and follow the quick on-screen instructions.
- 3. Start creating: Open WPS Writer, Spreadsheet, or Presentation and enjoy full compatibility with your existing Microsoft documents.

Frequently Asked Questions
How do I force Microsoft Graph PowerShell to ask for login credentials again?
To force a new authentication prompt and clear the local token cache, you can delete the '.graph' folder located in your local user profile directory, or use the 'Connect-MgGraph -ForceRefresh' parameter.
Does Disconnect-MgGraph revoke application permissions in Azure?
No. The Disconnect-MgGraph command only ends your active local PowerShell session. It does not revoke the admin consent or application permissions granted in Microsoft Entra ID. You must remove those manually via the Azure portal.
Why does Get-MgContext show scopes I didn't request in my current session?
Microsoft Graph PowerShell accumulates scopes over time. If you previously connected and granted consent to specific scopes, those permissions are cached in the application's service principal. Get-MgContext displays all cumulatively granted scopes, not just the ones requested in your most recent connection.




