How to change token expiration time in Azure portal - AAD - Microsoft Q&A (2024)

Hi @Sarah ,

Thanks for reaching out.

It is not possible to configure token lifetime using Azure AD portal.

However, you can request refresh token along with access token or IdToken by passing offline_access in scope parameter to get the refresh token which is used to obtain new access/refresh token pairs when the current access token expires. The refresh token lifetime by default is 90 days.

Other way to configure token lifetime is through powershell by creating policy as mentioned in the link you added.

Hope this will helps.



Please remember to "Accept Answer" if answer helped you.

How to change token expiration time in Azure portal - AAD - Microsoft Q&A (2024)


How do I change my Azure token expiration time? ›

You can configure token lifetimes in the Azure portal. Go to the Azure portal. In "Azure Active Directory" > "Security" > "Authentication methods" > "Authentication methods blade" > "Token Lifetime Policies". you can configure the lifetime of access tokens, refresh tokens, and ID tokens.

How do I change the expiration date on my Azure AD? ›

We cannot set any expiration for users in Azure AD as of now. If you are syncing users from on-premise AD to Azure AD then it is better to set the expiration in on-premise AD and create a rule in AD connect to disable the account post expiry.

How do I change my Azure portal timeout? ›

To enforce an idle timeout setting for all users of the Azure portal, sign in with a Global Administrator account, then select Enable directory level idle timeout to turn on the setting. Next, enter the Hours and Minutes for the maximum time that a user can be inactive before their session is automatically signed out.

How long does an Azure AD access token last? ›

Access and ID token lifetimes (minutes) - The lifetime of the OAuth 2.0 bearer token and ID tokens. The default is 60 minutes (1 hour). The minimum (inclusive) is 5 minutes. The maximum (inclusive) is 1,440 minutes (24 hours).

How can I increase my expiry token time? ›

Use Refresh Tokens: When you authenticate with OAuth2, you can request a refresh token in addition to an access token. The refresh token can be used to obtain a new access token when the current one expires, which can extend the expiration time of your authentication.

What is the default token expiration time? ›

User access tokens have an expiration time, which is set to 60 minutes by default. Follow the instructions below to change the default expiration time of user access tokens: Open the <API-M_HOME>/repository/conf/deployment. toml file.

How do I set my ad account to expire at a certain time? ›

The Set-ADAccountExpiration cmdlet sets the expiration time for a user, computer, or service account. To specify an exact time, use the DateTime parameter. To specify a time period from the current time, use the TimeSpan parameter. The Identity parameter specifies the Active Directory account to modify.

How to update Azure AD with a valid token signing certificate? ›

To update Azure AD with a valid token-signing certificate

Replace <servername> with the name of the AD FS server. Then enter the administrator credentials for the AD FS server when prompted. Optionally, verify whether an update is required by checking the current certificate information in Azure AD.

Where in the Azure portal would you go to configure an expiration policy? ›

To create a policy for your tenant, simply select Groups from the Azure Active Directory portal, and choose Expiration under 'Settings' , and configure the policy. Group owners will receive email notifications 30 days, 15 days, and 1 day before the expiration date.

What is the default session timeout in Azure portal? ›

Session timeout is a server side feature where life time of all sessions are enforced. Default values are: Maximum Session Length: 1440 minutes. Minimum Session Length: 60 minutes.

How do I change the authentication method in Azure portal? ›

Using Azure Portal:

Navigate to Azure Active Directory > Users > All users > Choose the user you wish to perform an action on > select Authentication methods > Require Re-register MFA. Once this is done, the next time the user signs in, he/she will be requested to set up a new MFA authentication method.

How do I keep Azure portal for free after 12 months? ›

You can sign up directly for pay as you go. This will enable you to immediately use services beyond the free amounts at pay-as-you-go rates. You'll still get monthly free amounts of popular services for 12 months2 and more than 55 services that are always free, but you won't receive the USD 200 credit.

What happens when a token expires? ›

In this article. When a token has expired or has been revoked, it can no longer be used to authenticate Git and API requests. It is not possible to restore an expired or revoked token, you or the application will need to create a new token.

What is the default access token lifetime in Azure AD? ›

The default lifetime of an access token is variable. When issued, an access token's default lifetime is assigned a random value ranging between 60-90 minutes (75 minutes on average).

How do I update my Azure refresh token? ›

Go to Services > Applications > Azure Cloud Solution Provider > instance name > Configuration tab > Manage Refresh Token. In the Manual Update group, specify the authorization code that you received and click Update. Make sure that a message like Your refresh token has been successfully updated is shown.

How long should refresh token expire? ›

The refresh token expires after 6 months (source: Access Token expires_in - #14 by jessicagarson)

What to do when refresh token expires? ›

The member must reauthorize your application when refresh tokens expire. When you use a refresh token to generate a new access token, the lifespan or Time To Live (TTL) of the refresh token remains the same as specified in the initial OAuth flow (365 days), and the new access token has a new TTL of 60 days.

Top Articles
Latest Posts
Article information

Author: Tuan Roob DDS

Last Updated:

Views: 6493

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Tuan Roob DDS

Birthday: 1999-11-20

Address: Suite 592 642 Pfannerstill Island, South Keila, LA 74970-3076

Phone: +9617721773649

Job: Marketing Producer

Hobby: Skydiving, Flag Football, Knitting, Running, Lego building, Hunting, Juggling

Introduction: My name is Tuan Roob DDS, I am a friendly, good, energetic, faithful, fantastic, gentle, enchanting person who loves writing and wants to share my knowledge and understanding with you.