Revoke employee browser sessions when access becomes a threat.

Strong Single Logout—called Nuke Sessions in Armory—clears local website sessions from connected Locke browser profiles, reloads open tabs, and revokes the employee's Locke sessions.

verifiedIncident containment | verifiedUrgent offboarding | verifiedMSP admin access

Two urgent situations. One browser-session gap.

Disabling an identity does not necessarily remove session material already stored in a browser. Locke gives IT a direct containment action while the rest of the response continues.

warning

An account or endpoint may be compromised

A live browser session can provide a path into email, file storage, billing, and other SaaS tools without another password prompt. Clear local session material first, then investigate the endpoint and revoke access at affected providers.

person_off

An employee must lose access now

A terminated or disgruntled employee may still be signed into third-party websites while directory and SaaS deprovisioning finish. Nuke Sessions clears those local browser sessions from connected profiles during the offboarding window.

Authorized MSP partners can run the same containment action for a client from the employee's Armory profile.

Three steps to contain the browser.

person_search

1. Select

Open the employee's Armory profile and choose Nuke Browser Sessions.

delete_sweep

2. Clear

Connected extensions clear cookies and site storage, then reload open web tabs.

lock_reset

3. Revoke

Locke sessions close and the extensions clear cached Locke credentials and keys.

Clear sessions without wiping the browser.

deleteCleared from connected profiles

  • Website cookies
  • Local storage and IndexedDB
  • Cache storage and service workers
  • Locke sessions, cached credentials, and keys

verified_userLeft in place

  • Saved passwords and bookmarks
  • Browsing history and downloads
  • Local files and form-fill data
  • Profiles without an authenticated Locke extension

Nuke Sessions complements account disablement, provider-side session revocation, endpoint isolation, investigation, and password rotation. It cannot recall a token already copied to another device.

Common questions

How is this different from revoking Locke sessions?expand_more
Standard revocation signs the employee out of Locke. Nuke Sessions also clears website cookies and site storage from connected Locke browser profiles and reloads open tabs.
What happens if a browser is offline?expand_more
Connected extensions receive the command immediately. A short-lived command waits for an extension that reconnects within five minutes.
Can the employee sign in again?expand_more
Yes. Nuke Sessions is a containment action, not a permanent access block. Complete normal offboarding and provider-side revocation to remove access.

When access has to stop now, start in Armory.

Strong Single Logout is included with Locke Armory for organization admins and authorized MSP partners.