User clicked on malicious url in email.
After change password, can existing session continue?
User clicked on malicious url in email.
After change password, can existing session continue?
Hi @TonyP-6592,
Yes, it can.
https://docs.microsoft.com/en-us/microsoft-365/enterprise/session-timeouts?view=o365-worldwide
@TonyP-6592
Thank you for your post!
Adding onto what TKujala linked, when users authenticate in any of the Microsoft 365 web apps or mobile apps, a session is established. For the duration of the session, users won't need to re-authenticate. Sessions can expire when users are inactive, when they close the browser or tab, or when their authentication token expires for other reasons such as when their password has been reset.
For more info on the different session timeouts:
If you have any other questions, please let me know.
Thank you for your time and patience throughout this issue.
Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.
2 people are following this question.