Active sessions
See who is signed in, and sign somebody out.
Go to Admin > Management > Active Sessions.
You need the View Users permission to open the page. You need Update Users to end a session.
The table
| Column | Description |
|---|---|
| User | The username and the email address of the account. |
| IP | The address that the session came from. |
| Device / Agent | The device name, or the browser identity of the session. |
| Last active | The date and time of the last request on the session. |
| Expires | The date and time when the session ends by itself. |
The list holds only the sessions that are still valid. The newest activity comes first. The page loads up to 100 rows.
The panel marks the row of the session that you use now. If you revoke that row, you sign yourself out.
When nobody is signed in, the page shows "No active sessions."
Refreshing
Click Refresh at the top right to load the list again. The page does not refresh by itself. It loads once when you open it, and again after each successful revoke.
Revoking one session
- Find the row.
- Click Revoke.
- Confirm the dialog.
The device signs out in seconds. The panel does not wait for the token to expire.
Revoking every session of a user
- Find any row for that user.
- Click Revoke all.
- Confirm the dialog.
The panel ends every session of that account and reports how many it ended. Use this action after a password reset, or when you suspect that somebody else used the account.
Limits of this page
- The page has no search box and no filters.
- The page has no tick boxes. Revoke all works on one user at a time. There is no control to end every session on the panel.
Audit
The panel records each revoke in the Activity Log. Read Activity Log.
Personal sessions
A user manages personal sessions from Account > Sessions. That page also holds a Revoke All Others button. Read Account Settings.
Next steps
- User Management - suspend or delete an account.
- Security Settings - session lifetime and login lockout.
