Overview
To maintain compliance of remote users connecting to your network, you can create a connector that automatically revokes a remote user session if their session is revoked in Microsoft Entra ID. For example, when an admin revokes a user's sessions in Entra ID (such as after a security incident, when a user leaves the organization, or as part of an automated flow), the user's session in the Cato Client is also revoked. This ensures your Entra ID security actions are consistently enforced across your Cato environment, reducing the risk of unauthorized access.
Within a few minutes of the session being revoked in Entra ID, the Client is disconnected, and the remote user is prompted to authenticate in the Client using their configured authentication method. This functionality applies only to remote users connecting with the Cato Client. It does not apply to the Enterprise Browser or Browser Extension.
For more information on revoking a remote user session in the Cato Client, see Revoking a Remote User Session. For more information on revoking a user session in Entra ID, see the Microsoft documentation.
Prerequisites
The remote user must be provisioned from Entra ID and use Entra ID SSO for authentication. For more information, see SCIM Provisioning with Entra ID
To revoke a session from an automated flow in Entra ID, a Microsoft Entra ID P2 license is required
Configuring the Revoke Session Connector
To configure the Revoke Session connector, you need to:
Create a Microsoft 365 Tenant integration as the parent connector
Create the API connector for Revoke Session
Step 1: Create the Microsoft 365 Tenant Integration
First, configure the Microsoft 365 Tenant integration as the parent connector. This connector can be used for all Microsoft integrations. If you have already created the parent connector, go to step 2.
To create the Microsoft 365 Tenant integration:
From the navigation menu, select Resources > Integrations and click the Integrated Apps tab.
Click New. The New Connector panel opens.
In the New Connector panel, select the Microsoft 365 (New Tenant) app.
.png?sv=2026-02-06&spr=https&st=2026-10-04T23%3A45%3A28Z&se=2026-10-04T23%3A57%3A28Z&sr=c&sp=r&sig=1iQnEMsDLtkMlP0qeCiASAC4%2BoJiIHLbC4C7bY9hgcE%3D)
Enter the Connector Name.
Click Authorize and Save.
A new browser tab opens to the Microsoft 365 app.
In the new browser tab, authenticate to the Microsoft 365 app:
Select the Microsoft account for the Microsoft 365 app.
Otherwise, there may be a Microsoft authentication error.
Enter the password for the app and approve it.
Accept the permissions to let Cato access the Microsoft 365 app.
The screen shows that you have successfully applied the permissions for the app.

You can close the browser tab and return to the Cato Management Application.
The Microsoft 365 SaaS application is added to the Integrated Apps tab.
Step 2: Create the API connector for Revoke Session
After you have set up the parent connector, add the details of the Interconnected Apps integration in the CMA.
To create the API connector in the CMA:
From the navigation menu, click Resources > Integrations.
Click the Configured Integrations tab.
Click New.
The New Integration panel opens.
Select Microsoft Entra ID.
Choose Entra Revoke Session.
.png?sv=2026-02-06&spr=https&st=2026-10-04T23%3A45%3A28Z&se=2026-10-04T23%3A57%3A28Z&sr=c&sp=r&sig=1iQnEMsDLtkMlP0qeCiASAC4%2BoJiIHLbC4C7bY9hgcE%3D)
In the Auth drop-down, select the Microsoft Primary Tenant that was created in Step 1.
Add a Name for the connector.
Click Save.
The CMA connects to the vendor
Click Authorize.

A Microsoft permissions screen will appear.
Review the requested permissions and click Accept.
The app is visible on the Integrated Apps table with a Connected status.