Entra ID & IdentityHow-To & HardeningRetrospectives

How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must re-authenticate. Here is how to configure them in Entra ID.

Understand the defaults

By default, Entra ID uses a rolling sign-in window that keeps users signed in for long periods as long as they keep using their apps. That is convenient, but it also means a stolen refresh token can stay useful for a long time.

Step 1: Identify sensitive scenarios

Apply stricter controls where it matters:

  • Administrators and privileged role activation.
  • Access from unmanaged or personal devices.
  • High-risk sign-ins (Entra ID P2).
  • Sensitive applications such as finance or HR systems.

Step 2: Configure sign-in frequency

Create Conditional Access policies with the Sign-in frequency session control:

  • Admin portals: require reauthentication every few hours.
  • Unmanaged devices: require reauthentication daily or more often, and disable persistent browser sessions.
  • Risky sign-ins: require reauthentication every time.

Step 3: Disable persistent browser sessions on unmanaged devices

Use the Persistent browser session control set to "Never persistent" for browser access from non-compliant devices.

Step 4: Enable Continuous Access Evaluation

CAE lets supported services revoke access in near real time when a user is disabled, a password is reset or a network location changes. It is on by default for most tenants; review your settings.

Step 5: Add token protection where supported

Token protection binds sign-in session tokens to the device they were issued to, for supported clients and apps. Pilot it for high-value users.

Balance

Overly frequent prompts train users to approve anything. Apply strict controls to risky contexts and keep everyday access smooth.

conditional access sign-in frequencyFacebook View As token theft2018

More on this story