Azure freaking AD does not, at all, support access token revocation.
Can you use a strategy like fusionauth.io/learn/expert-a… Or maybe use dpop to bind the token to the client, reducing risk? Something like this? learn.microsoft.com/en-us/entra/ms…
I would extract Azure AD’s public key, do my own token validation for identity tokens and use Redis to do my own revocation, and dance afterwards.
…. Has a potential 15 minute delay in Azure. Booo.
There is no token revocation in Azure AD. Period.
There is actually one trick you can do if you absolutely need to. 😁 If you have on-prem exchange, you can migrate the user’s mailbox to on-prem and then migrate it back to O365.
Azure is so limited in everything.... Had it for my site a few years ago and it was so frustrating... Thier control panel was such a mess
went though the same issue about 6 months ago, went with #aws #cognito. Other issues(like you cannot backup your cognito database without external tools..ugh) but the revocation works
Wait, Azure AD Threat Protection service doesn’t allow this?
Can’t you do this in Microsoft Defender for Cloud Apps? (I acknowledge that this is an extremely weird place for this, but it’s where I happen to do it)
Azure not supporting sending parallel instances a list of folder, only file list in batches…
Aren't access tokens good for like 2 minutes after which you need to request a new access token using the refresh token? 🤔
United States 趨勢
- 1. Ravens 57.4K posts
- 2. Lamar 46K posts
- 3. Bengals 51.3K posts
- 4. #heatedrivalry 11.2K posts
- 5. ilya 14.5K posts
- 6. shane 17K posts
- 7. Joe Burrow 20.5K posts
- 8. Zay Flowers 4,102 posts
- 9. Cowboys 92.7K posts
- 10. Chiefs 108K posts
- 11. Hudson 11.4K posts
- 12. #WhoDey 3,669 posts
- 13. Derrick Henry 4,424 posts
- 14. Perine 1,581 posts
- 15. #hrspoilers 1,477 posts
- 16. connor storrie 1,781 posts
- 17. Harbaugh 3,114 posts
- 18. Sarah Beckstrom 212K posts
- 19. Zac Taylor 2,610 posts
- 20. AFC North 2,316 posts
Something went wrong.
Something went wrong.