"Revoke All" is the nuclear option. For lesser incidents — a borrowed phone, a friend who logged into your app to test something, a session you're suspicious of — finer-grained controls hurt less.
1. Revoke one session
The admin sessions page lists every active session: token (truncated), IP, created, expires. Each row has its own delete button.
2. Revoke by IP
If you suspect a specific IP, revoke its sessions and blacklist it in one operation.
3. Tighten lockout during incident
If you're under active brute force, drop the retry limit from 5 to 2 with one update. Restore later.
4. Disable local IP bypass temporarily
If the attacker might be on your LAN (kid's friend, suspicious house guest, compromised IoT), removing the local bypass forces them through the PIN gate too.