You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Microsoft Entra External ID原生认证时刷新令牌12小时过期问题

Entra External ID原生认证Refresh Token过期异常问题

问题描述

我们采用Microsoft Entra External ID的CIAM方案实现外部消费者身份认证,使用官方的Android和iOS原生认证示例(ms-identity-ciam-native-auth-android-sample、ms-identity-ciam-native-auth-ios-sample),通过OTP完成用户注册与登录,后端已严格按文档配置好原生认证+OTP用户流的全部内容。

在使用Native Authentication时遇到Refresh Token相关问题:

  • 按官方说明,非单页应用的Refresh Token默认有效期应为90天:

refresh tokens的默认有效期:单页应用为24小时,其他场景为90天。

  • 但实际Refresh Token仅12小时无活动就过期,导致应用强制用户重复登录,体验极差,错误提示如下:

AADSTS700082: The refresh token has expired due to inactivity. The token was issued on 2024-09-25T13:42:23.0482303Z and was inactive for 12:00:00.

排查过程

我们尝试了官方推荐的解决方法,但均无法生效:

  • 无法配置Refresh Token生命周期策略:原Refresh Token和会话令牌的令牌生命周期策略方案自2021年1月30日起已废弃,通过Graph API的/policies/tokenLifetimePolicies端点设置时返回错误:
{
    "error": {
        "code": "Request_BadRequest",
        "message": "Configure Token Lifetime for RT/ST (Refresh/Session Token) is retired and all policies will not be honored anymore Refer  https://go.microsoft.com/fwlink/?linkid=2153669 for more information",
        "details": [
            {
                "code": "UnsupportedPolicyProperty",
                "message": "Configure Token Lifetime for RT/ST (Refresh/Session Token) is retired and all policies will not be honored anymore Refer  https://go.microsoft.com/fwlink/?linkid=2153669 for more information",
                "target": "PolicyDetail"
            }
        ],
        "innerError": {
            "date": "2024-10-03T08:41:07",
            "request-id": "<uuid>",
            "client-request-id": "<uuid>"
        }
    }
}
  • 无法配置自适应会话生命周期策略或登录频率控制:Entra External ID中的Session Controls功能处于禁用状态(按钮显示“不可用”),无法进行相关配置。

内容的提问来源于stack exchange,提问作者nicolaa5

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 19:25:09