How to Sign Out All Microsoft 365 Sessions After a Password Change
Question details
An organization updated the password for a shared email account and needs to revoke access for remote users who might still be logged in using the old credentials.
- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Securing a shared front-desk email account after a routine or forced password update.
- Observed behavior
- Merely changing the password allows existing access tokens to remain valid temporarily, meaning remote devices can still access the account.
Ensure you have administrator privileges in Microsoft 365, as standard users cannot access the admin portal to force global sign-outs for other organization accounts.
Force Sign Out via the Microsoft 365 Admin Center
Revoke all active sessions and access tokens for a specific user to force immediate re-authentication.
When you change a password in Microsoft 365, devices already logged in may not be kicked out immediately. This happens because Microsoft uses access tokens for authentication, and existing tokens remain valid until they expire.
By manually triggering the 'Sign out of all sessions' command in the admin portal, you immediately invalidate those active tokens.
Open a web browser and sign in to the Microsoft 365 admin center using your administrator credentials.
From the left-hand navigation menu, click on 'Users' and then select 'Active users'.
Find and click on the specific user account (e.g., the shared front-desk email) to open their account properties panel on the right side of the screen.
Click on the 'Account' tab in the properties panel, scroll down if necessary, and click the 'Sign out of all sessions' link.
Manage Documents Securely with WPS Office
Looking for a cost-effective and secure office suite for your team? WPS Office is a lightweight, highly compatible alternative to Microsoft Office. It offers robust local document security, easy collaboration, and an intuitive interface without the hassle of complex cloud administration panels.

Frequently Asked Questions
Why are users still logged into Microsoft 365 after I changed the password?
Microsoft 365 relies on access tokens rather than continuous password checks. When you change a password, it prevents new logins, but existing active sessions remain valid until their tokens expire. You must manually revoke sessions to force immediate logouts.
How long does it take for a forced sign-out to take effect in Microsoft 365?
After an administrator clicks 'Sign out of all sessions' in the admin center, it typically takes up to 15 minutes for the command to propagate across Microsoft's servers and disconnect all devices.
Can I sign out of all devices without administrator access?
Yes, if you want to sign yourself out of your own account, you can log into your Microsoft Account profile online, navigate to the 'Security' settings, and choose the option to sign out everywhere. However, you cannot do this for other users without admin rights.




