Lukas Beran · @lukasberancz
14 followers · 20 posts · Server infosec.exchange

and in is important in terms of responding to affecting Azure AD. How and when do tokens expire or what are the revocation options?

tokens typically have an expiration time of 60 minutes. And there is no way to manually invalidate an access token except by manually deleting the token in the cache on the device.

tokens typically have a default expiration of 90 days. However, refresh tokens can be invalidated by an admin from the Azure portal or using PowerShell or the Graph API.

A Primary Refresh Token () is invalidated when the Azure AD account is disabled or deleted, the user password is changed or reset, or the device where the PRT was issued is disabled or deleted.

#token #revocation #expiration #azuread #security #incidents #access #refresh #prt

Last updated 1 year ago

Kent Pitman · @kentpitman
354 followers · 304 posts · Server climatejustice.social
PSiReN-X · @PSiReN
3 followers · 610 posts · Server vmst.io
Lukas Beran · @lukasberancz
6 followers · 10 posts · Server infosec.exchange

for accounts no longer makes sense and is not recommended if multi-factor authentication () is used. For this reason, it is recommended to disable password expiration in the environment as well.

But what if the company has synchronized identities in the Password Hash Sync () scenario? In that case, the password expiration policy is not applied to the synchronized accounts. And such accounts passwords are always set to never expire. It is assumed that in such a case the policy in Active Directory handles this.

But what if the user never authenticates to the local AD? The computer has Azure AD Join and the user is only using cloud services. The password for his AD account has expired, but he doesn't even know about it, and Azure AD still authenticates the user because passwords for synchronized accounts never expire.

In this case, you need to configure the Azure AD Connect server to apply the Azure AD password expiration policy also to synchronized accounts. This can be done using PowerShell on the Azure AD Connect server: Set-MsolDirSyncFeature -Feature EnforceCloudPasswordPolicyForPasswordSyncedUsers

#password #expiration #mfa #microsoft365 #phs #azuread

Last updated 2 years ago

Kenny · @kennyc
285 followers · 1017 posts · Server mastodon.social
Lukas Beran · @lukasberancz
6 followers · 8 posts · Server infosec.exchange

for synchronized accounts. A thing that many administrators don't know about.

If you have a password expiration set in , this expiration is not synchronized by default to Azure AD. So, an account that has an expired password in Active Directory is still usable within Azure AD, and the user is not even notified that their password has expired. The same goes for accounts that have a flag set that the user must change their password the during next log on - this is not reflected in Azure AD and the password valid permanently.

Both things are configurable via PowerShell on the Azure AD Connect server though.

#password #expiration #azuread #activedirectory

Last updated 2 years ago

Humanary Stew · @feldspa
120 followers · 453 posts · Server mas.to

Did you get a free test kit recently? Check the expiration date. My kit is in 10 days. My mom's kit expiration is 6-27-22. We got these kits less than a week ago.

#expiration #covid

Last updated 2 years ago

Parliamo di news! · @parliamodinews
16 followers · 87657 posts · Server masthead.social
Peter V. Tretter ✅ 🇨🇦 · @ap236
257 followers · 7864 posts · Server mastodon.social

Ontario has killed the licence plate sticker, but drivers still need to renew bit.ly/3mzWYDe

#licenceplates #driving #expiration #onpoli

Last updated 2 years ago

Grégory PAUL · @paulgreg
130 followers · 1646 posts · Server framapiaf.org

Let's Encrypt's Root Certificate is expiring! (that may break connection to websites on a lot of devices) scotthelme.co.uk/lets-encrypt-

#tls #security #letsencrypt #certificate #expiration

Last updated 3 years ago

mleduc · @mleduc
36 followers · 313 posts · Server framapiaf.org

C'est définitivement Noël 😍

RT @lamethodeFC@twitter.com

[ANNONCE] On vous prépare un particulier cette semaine ! Nous recevrons l'auteur de pour 1h de discussion autour de son oeuvre, suite à la parution de son 2e recueil de nouvelles en France : bit.ly/36P3Vt1 aux @EDITIONSDENOEL@twitter.com

🐦🔗: twitter.com/lamethodeFC/status

#vendredifiction #sf #tedchiang #expiration

Last updated 4 years ago

POUJOL-ROST Mathias ✅ · @poujolrost
273 followers · 10760 posts · Server mstdn.jp

@Quadragondin
Oui un méga problème affecte bcp de monde… en cours de résolution paraît-il… ( d'un )

#certificat #expiration #firefox

Last updated 6 years ago