Azure freaking AD does not, at all, support access token revocation.


Can you use a strategy like fusionauth.io/learn/expert-a… Or maybe use dpop to bind the token to the client, reducing risk? Something like this? learn.microsoft.com/en-us/entra/ms…


I would extract Azure AD’s public key, do my own token validation for identity tokens and use Redis to do my own revocation, and dance afterwards.


Continuous access evaluation?


…. Has a potential 15 minute delay in Azure. Booo.


There is no token revocation in Azure AD. Period.


You have a problem with job security?


It also really shouldn’t be named azure ad


There is actually one trick you can do if you absolutely need to. 😁 If you have on-prem exchange, you can migrate the user’s mailbox to on-prem and then migrate it back to O365.


Passive directory


Azure is so limited in everything.... Had it for my site a few years ago and it was so frustrating... Thier control panel was such a mess


went though the same issue about 6 months ago, went with #aws #cognito. Other issues(like you cannot backup your cognito database without external tools..ugh) but the revocation works


Welcome :) It is just a tip of the mountain :) recommend to read @DrAzureAD


Can’t you do this in Microsoft Defender for Cloud Apps? (I acknowledge that this is an extremely weird place for this, but it’s where I happen to do it)


Wait, Azure AD Threat Protection service doesn’t allow this?


Tied together with rubber bands and tape.


Azure not supporting sending parallel instances a list of folder, only file list in batches…


Aren't access tokens good for like 2 minutes after which you need to request a new access token using the refresh token? 🤔


It’s this just a feature of bearer tokens ?


United States Trends
Loading...

Something went wrong.


Something went wrong.