Consider the following scenario.
I have a user provisioned to O365 using WS-FED/Dirsync. That user is logged in and active within an O365 thin client session. If I disabled the user in AD, the user is deprovisioned from Okta during the next AD Import. They are also deactivated in O365 during the next Dirsync replication. If they were already active in O365 at that time, how long will their session remain active? Is there an active session expiry which happens to that user or do they still have access to O365 for some time after?
It looks like this is configurable for an Office365 organization, and varies by which application is in question, but typically is about 8 hours. See these links for more details
I hope that helps
Original Author: Alan Goho, Sr. Technical Consultant, Okta