Ability to reset active sessions for individual users

XMLWordPrintable

    • 1

      Currently, session duration and resets are managed globally via Authentication Policies. There is no native button in the Atlassian Administration UI to target and invalidate all active sessions (web and mobile) for a specific individual user without deactivating them or changing their policy.

       

      Description:
      Administrators need the ability to immediately terminate all active sessions for a specific user (e.g., during a security incident or immediate offboarding) without affecting other users in the same authentication policy.

      Proposed Solution:
      Add a "Reset All Active Sessions" or "Revoke All Tokens" button within the User Details page in admin.atlassian.com. This action should:

      1. Invalidate all current browser session cookies for that user.
      1. Revoke all OAuth tokens used by mobile applications (Jira/Confluence apps).
      1. Force the user to re-authenticate upon their next action.

      Current Workaround:

      • Deactivating the user.
      • Moving the user to a temporary "Strict" authentication policy with a very short session duration (though this is not immediate).
      • Manually removing product access.

              Assignee:
              Unassigned
              Reporter:
              Nagabharana S
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: