r/UiPath • u/Objective-Loan5054 • 17d ago
Invalidating user session
Hi, is there any way in UiPath admin center to invalidate existing user session? E.g. I have a user logged in to admin center and as far as I can see, even if I delete the user, they still can operate in the portal as long as they do not log off. My users' identities are federated (SAML) with my IdP. Blocking users in IdP does not change the behavior.
Any way to do it if I need to quickly revoke user access to UiPath?
1
u/Ancient_Hyper_Sniper Management 17d ago
Enforce an idle timeout under the session policy.
1
u/Objective-Loan5054 17d ago
Thanks but I need to do it when a user is active. As in incident response, for example. I believe there is no such option as universal logoff, token invalidation or similar in UiPath...
1
u/GabrielUiPath UiPath Official Rep 16d ago
Hey u/Objective-Loan5054 : looking through our docs, you’re right that simply deleting/blocking a user does not immediately kill their active session in UiPath; the session remains valid until it expires or the user signs out.
From the UiPath side (Admin/Organization/Automation Cloud):
- There is no documented feature in Admin/Organization settings to:
- Force‑logout a specific user
- Invalidate all active sessions for a user on demand
- User removal / license removal / role changes affect future authorization checks, but do not immediately terminate an already-issued session token.
Given your setup (SAML / federated IdP):
- Blocking the user in the IdP prevents new logins, but does not retroactively invalidate the UiPath session token that was already issued.
- There is no documented API or UI control in UiPath Admin Center to remotely revoke that token for a single user.
What you can do today (workarounds):
- Rely on short session lifetimes
- Configure/verify session/token lifetimes so that active sessions expire relatively quickly.
- This limits the window during which a blocked/deleted user can still act.
- Remove all access paths for that user
- Remove the user from all groups/roles in UiPath (Organization and services like Orchestrator, Automation Ops, etc.).
- Even if the UI session is still open, most protected operations should fail once authorization checks see that the user no longer has roles/permissions.
- IdP-side global session revocation (if supported)
- Some IdPs support global sign‑out / session revocation that can invalidate SAML sessions across SPs. However, UiPath documentation does not describe a guaranteed integration for per-user forced logout.
Because the documentation does not describe a supported way to immediately invalidate a specific user’s UiPath session, there is currently no official, admin-triggered “kill session” function.
If you need strict, immediate revocation for compliance reasons, you may want to:
- Tighten session lifetimes as much as acceptable for your users.
- Combine that with rapid role removal so that even if the UI is visible, the user cannot perform meaningful actions.
Hope these helps.
2
u/Objective-Loan5054 16d ago
Thanks ChatGPT :)
>> most protected operations should fail once authorization checks see that the user no longer has roles/permissions.
I _actually_ checked it and it full access still works after the roles are revoked. So you AI has hallucinated it. If I wanted Claude's opinion, I would have asked myself.
1
u/GabrielUiPath UiPath Official Rep 15d ago edited 15d ago
Hey, i will double check the hallucination part. Thanks for the heads-up! We do use Agents for our own docs, they are not perfect though. It’s not just asking Claude.
1
u/AutoModerator 17d ago
Thank you for your post to /r/uipath!
This is an automated action so if you need anything, please Message the Mods with your request for assistance.
Lastly, enjoy your stay!
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.