A credential an application hands to an API or other resource to prove what it has been authorised to do for a signed-in user. It deals with permissions, unlike the ID token, which records the sign-in itself.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Access token in context, with comparison tables and the common traps.
Terms in this definition
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.
- ID token
A token handed to an application after sign-in that confirms the user was authenticated and carries details about who they are. Calling an API needs a separate access token, which is about authorisation.
Related terms
- Bearer token
Access token placed in an HTTP
Authorization: Bearerheader; any party holding it can call the API it protects. - CAE
Instead of letting an access token run until it expires, Microsoft Entra continuous access evaluation allows Microsoft Graph, Teams, SharePoint Online, Exchange Online and similar services to end a session almost straight away. Triggers include a disabled account, a password reset, revoked tokens, high user risk or a move to a different network location.
- Refresh token
Clients trade this in for new access tokens, and it lives far longer than they do (by default 90 days, or 24 hours in a single-page app). Revoking someone's sessions kills it, yet any access token they already hold keeps working until its own expiry.
- Set-Authentication
Saves a Microsoft Entra access token so the scanner, or labelling cmdlets, can run unattended. Part of the Purview Information Protection client, it takes parameters like OnBehalfOf and DelegatedUser.
- SID
Every Windows or Active Directory user, group and computer gets one, unique and never handed out again. Windows puts it in a person's access token when they log on.