Glossary
Sign-in cookies reset
An admin action that signs a Google Workspace user out of all browser sessions, evicting stolen sessions after an account takeover.
Resetting sign-in cookies (Directory → Users → user → Security → Sign-in cookies → Reset in the Admin console, or the Directory API users.signOut) signs the user out of their Google sessions on every device and browser. The next access requires a fresh sign-in.
It is the containment step against session theft, including adversary-in-the-middle phishing. The attacker's copied session stops working. It doesn't revoke OAuth tokens, forwarding or filters, so do those separately. With a third-party IdP, also end the IdP session.