strazactl devices revoke
Revoke a device enrollment (its device credential stops minting sessions)
On this page
Synopsis
Removes the device enrollment: the long-lived device credential minted at
enroll can no longer start sessions, sessions bound to the device stop
refreshing, and a live enforcement kit on it is stood down by push. The user
is untouched: they re-enroll the machine (or a replacement) with a fresh
interactive login. For a person-level cut, use users disable or users lock.
strazactl devices revoke <username> <device-id> [flags]
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl devices: Inspect and revoke a user’s enrolled devices