How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access
Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.
Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must re-authenticate. Here is how to configure them in Entra ID.
Understand the defaults
By default, Entra ID uses a rolling sign-in window that keeps users signed in for long periods as long as they keep using their apps. That is convenient, but it also means a stolen refresh token can stay useful for a long time.
Step 1: Identify sensitive scenarios
Apply stricter controls where it matters:
- Administrators and privileged role activation.
- Access from unmanaged or personal devices.
- High-risk sign-ins (Entra ID P2).
- Sensitive applications such as finance or HR systems.
Step 2: Configure sign-in frequency
Create Conditional Access policies with the Sign-in frequency session control:
- Admin portals: require reauthentication every few hours.
- Unmanaged devices: require reauthentication daily or more often, and disable persistent browser sessions.
- Risky sign-ins: require reauthentication every time.
Step 3: Disable persistent browser sessions on unmanaged devices
Use the Persistent browser session control set to "Never persistent" for browser access from non-compliant devices.
Step 4: Enable Continuous Access Evaluation
CAE lets supported services revoke access in near real time when a user is disabled, a password is reset or a network location changes. It is on by default for most tenants; review your settings.
Step 5: Add token protection where supported
Token protection binds sign-in session tokens to the device they were issued to, for supported clients and apps. Pilot it for high-value users.
Balance
Overly frequent prompts train users to approve anything. Apply strict controls to risky contexts and keep everyday access smooth.
- Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen Incident Teardowns
- Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You CIO Briefings