79111338

Date: 2024-10-21 18:39:14
Score: 3
Natty:
Report link

Thank you for your feedback. We've confirmed this behavior of a 12h Refresh Token is impacting Microsoft Entra External ID, and it is specific to the Email OTP flow. It was caused by a change to Entra made for security. One workaround until it is addressed is to use a username/password flow.

Before relaxing the Refresh Token lifetime back to 90 days, the team currently has prioritized fixing Conditional Access for Session Controls in the Email OTP scenario. We are interested in your feedback, does your Email OTP scenario require Conditional Access policy such as MFA?

Reasons:
  • Blacklisted phrase (0.5): Thank you
  • Long answer (-0.5):
  • No code block (0.5):
  • Ends in question mark (2):
  • Low reputation (0.5):
Posted by: Saeed Akhter