Azure freaking AD does not, at all, support access token revocation.
Can you use a strategy like fusionauth.io/learn/expert-a… Or maybe use dpop to bind the token to the client, reducing risk? Something like this? learn.microsoft.com/en-us/entra/ms…
I would extract Azure AD’s public key, do my own token validation for identity tokens and use Redis to do my own revocation, and dance afterwards.
…. Has a potential 15 minute delay in Azure. Booo.
There is no token revocation in Azure AD. Period.
There is actually one trick you can do if you absolutely need to. 😁 If you have on-prem exchange, you can migrate the user’s mailbox to on-prem and then migrate it back to O365.
Azure is so limited in everything.... Had it for my site a few years ago and it was so frustrating... Thier control panel was such a mess
went though the same issue about 6 months ago, went with #aws #cognito. Other issues(like you cannot backup your cognito database without external tools..ugh) but the revocation works
Can’t you do this in Microsoft Defender for Cloud Apps? (I acknowledge that this is an extremely weird place for this, but it’s where I happen to do it)
Wait, Azure AD Threat Protection service doesn’t allow this?
Azure not supporting sending parallel instances a list of folder, only file list in batches…
Aren't access tokens good for like 2 minutes after which you need to request a new access token using the refresh token? 🤔
United States Trends
- 1. #DWTS 87K posts
- 2. Luka 40.2K posts
- 3. Robert 125K posts
- 4. Alix 14.4K posts
- 5. Elaine 44.6K posts
- 6. Clippers 10.2K posts
- 7. Jordan 119K posts
- 8. Dylan 35.2K posts
- 9. NORMANI 5,426 posts
- 10. Collar 35.8K posts
- 11. #DancingWithTheStars 2,208 posts
- 12. Kawhi 3,593 posts
- 13. Carrie Ann 4,169 posts
- 14. Daniella 3,928 posts
- 15. Anthony Black 3,346 posts
- 16. Bennett Stirtz N/A
- 17. Godzilla 35.1K posts
- 18. Drummond 3,132 posts
- 19. Donovan Dent N/A
- 20. Kobe Brown N/A
Something went wrong.
Something went wrong.