Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Glossary

Sign-in cookies reset

An admin action that signs a Google Workspace user out of all browser sessions, evicting stolen sessions after an account takeover.

Resetting sign-in cookies (Directory → Users → user → Security → Sign-in cookies → Reset in the Admin console, or the Directory API users.signOut) signs the user out of their Google sessions on every device and browser. The next access requires a fresh sign-in.

It is the containment step against session theft, including adversary-in-the-middle phishing. The attacker's copied session stops working. It doesn't revoke OAuth tokens, forwarding or filters, so do those separately. With a third-party IdP, also end the IdP session.

See: first-hour incident response checklist.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.