Clients trade this in for new access tokens, and it lives far longer than they do (by default 90 days, or 24 hours in a single-page app). Revoking someone's sessions kills it, yet any access token they already hold keeps working until its own expiry.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Refresh token in context, with comparison tables and the common traps.
Terms in this definition
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Access token
A credential an application hands to an API or other resource to prove what it has been authorised to do for a signed-in user. It deals with permissions, unlike the ID token, which records the sign-in itself.
Related terms
- Non-interactive sign-ins
Sign-ins carried out for a user by a client app or operating system component using an authorisation code or refresh token, with no factor entered by the user. They have their own log, separate from interactive sign-ins, and identical ones are grouped together.
- service account
An account for software rather than people, letting scripts or applications call an API; in VCF Automation, for example, such accounts sign in using a refresh token.