Revoking access

Updated September 7, 2026

Consent can be withdrawn at any time, from inside your own tenant, without contacting us and without notice. Revoking access and erasing stored data are two separate operations, and this page covers both.

How to revoke

  1. In the Azure portal, open Microsoft Entra ID → Enterprise applications.
  2. Find Token Watch and delete it, or remove its permission grants.

Nothing is required from us, and there is no notice period or offboarding process to wait on.

What stops

Microsoft Graph reads Stop at the next token request, which fails against your tenant. No further data leaves your tenant.
The scheduled check Stops producing results for your tenant. Alerts that depend on a successful read stop with it.
Sign-in Deleting the enterprise application also removes the sign-in integration, so your users can no longer sign in to Token Watch.

Because Token Watch installs nothing in your environment, there is nothing to uninstall afterwards. No agent, no service account, no firewall rule, and no scheduled task remains behind.

Data retention after revoking consent

Revoking consent does not erase the credential metadata and configuration already written to our database. Those records stay until they are deleted, and deletion is a separate request.

The retention and deletion page sets out what is held, how to have a tenant erased, the timeframe committed to, and what persists in backups afterwards. Email contact@aztokenwatch.com to start it. Revoking first and requesting deletion afterwards is fine, and so is the reverse order.

Related

Top