When access becomes a threat, clear the browser.

Whether an attacker stole a session or a disgruntled employee just walked out, one action in Armory clears their website sessions, reloads open tabs, and revokes every Locke session.

verifiedBrowser-Wide Clearing | verifiedImmediate Locke Revocation | verifiedMSP Admin Access

Three steps to contain the browser.

person_search

1. Select

Open the employee's profile in Armory and choose Nuke Browser Sessions.

delete_sweep

2. Clear

Connected extensions clear cookies and site storage, then reload open web tabs.

lock_reset

3. Revoke

Locke sessions close and the extensions clear their cached credentials and keys.

Two threats. The same browser-session gap.

Existing app sessions can remain while tokens expire and deprovisioning reaches each service. Nuke Sessions removes the local session material from the browser itself.

warning

Suspected Compromise

An attacker who controls a signed-in browser can move from email to storage, billing, social accounts, and admin tools without entering another password. Clear the local sessions first, then continue the investigation and revoke access at affected providers.

person_off

A Disgruntled Employee

Disabling the Microsoft account does not instantly sign someone out of every SaaS tool, especially websites outside your tenant. Clear the browser while directory and provider-side deprovisioning catch up.

Authorized MSP partners can run the same containment action for a client directly from the employee's Armory profile.

Microsoft says Entra app provisioning typically runs every 20 to 40 minutes. Session behavior still depends on each application. Read Microsoft's guidance.

Sessions go. Personal browser data stays.

deleteCleared

  • Website cookies
  • Local storage and IndexedDB
  • Cache storage and service workers
  • Locke sessions, cached credentials, and keys

verified_userPreserved

  • Saved passwords and bookmarks
  • Browsing history and downloads
  • Local files and form-fill data
  • Profiles without an authenticated Locke extension

Nuke Sessions is one containment step. Keep using your normal account disablement, provider-side revocation, endpoint investigation, and password-rotation process.

Common Questions

How is this different from revoking Locke sessions?expand_more

Revoking sessions signs the employee out of Locke. Nuke Sessions also clears website cookies and site storage from their connected Locke browser profiles and reloads open website tabs.

What happens if a browser is offline?expand_more

Connected extensions receive the command immediately. A short-lived command waits for an extension that reconnects within five minutes.

Can the employee sign in again?expand_more

Yes. Nuke Sessions is a containment action, not a ban. The employee can sign in again anywhere they still have valid credentials and access.

When access has to stop now, start in Armory.

Nuke Sessions is included with Locke Armory for organization admins and authorized MSP partners.