Revoking a session in the Enterprise Console now does what admins expect. Previously, revoking a session could appear ineffective: the user's browser would silently re-authenticate through SSO (a 302 redirect) and get a fresh session almost immediately. The Console now offers a "Revoke and block future authentication" option that stops that loop.
Highlights:
- Revoke and block – The session revocation dialog adds a secondary option to block the user from re-authenticating, not just to end the current session.
- No more silent re-auth – Blocking prevents the SSO re-authentication loop, so a revoked user stays out instead of bouncing back in through the IdP.
- Policy-backed enforcement – Blocked users are added to a deny/revocation list so the block is enforced on subsequent requests.
This was a direct response to enterprise customer feedback and closes a real gap in incident response, where "revoke" needs to mean the user is actually out.
See the Enterprise Console docs for session management.
