keycloak-scim/server_admin/topics/sessions/administering.adoc
2021-09-21 08:58:46 +02:00

32 lines
1.4 KiB
Text

=== Administering Sessions
To see a top-level view of the active clients and sessions in {project_name}, click *Sessions* from the menu.
.Sessions
image:{project_images}/sessions.png[]
==== The *Logout all* Operation
You can log out all users in the realm by clicking the *Logout all* button.
When you click the *Logout all* button, all SSO cookies become invalid, and clients requesting authentication within active browser sessions must log in again. {project_name} notifies clients by using the {project_name} OIDC client adapter of the logout event. Client types such as SAML do not receive a back-channel logout request.
[NOTE]
====
Clicking *Logout all* does not revoke outstanding access tokens. Outstanding tokens must expire naturally. For clients using the {project_name} OIDC client adapter, you can push a <<_revocation-policy, revocation policy>> to revoke the token, but this does not work for other adapters.
====
==== Application Navigation
On the `Sessions` page, you can click on each client to go to that client's `Sessions` tab. Click the *Show Sessions* button there to see which users are in the application.
.Application Sessions
image:{project_images}/application-sessions.png[]
==== User Navigation
If you go to the `Sessions` tab of an individual user, you can also view the user's session information.
.User Sessions
image:{project_images}/user-sessions.png[]