Skip to content
Entra Refresh Tokens Valid for 90 Days Key Actions based on your Licensing Entra ID Free E3 P1 and E5 P2

Entra Refresh Tokens Valid for 90 Days Key Actions based on your Licensing Entra ID Free E3 P1 and E5 P2

Written By Anoop C Nair
Last Updated February 12, 2025
Posted In Entra
SHARE

Let’s discuss Entra Refresh Tokens Valid for 90 Days Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2. Microsoft extended the default validity of the Entra Refresh token to 90 days. Before the recent update, the validity of tokens was typically 14-90 days, depending on the configuration.

Refresh tokens themselves do not require a specific license. However, your organization’s ability to configure and manage them effectively depends on the type of licensing it has with Microsoft. Key actions include Conditional Access Policies, Token Protection, Regular Credential Updates, etc.

Do you know what a Refresh token is? In the OAuth 2.0 authorization framework, refresh tokens are used to obtain a new access token without requiring the user to re-authenticate. They are issued along with the access token.

To enhance security, you can take specific actions depending on your licensing. In this blog post, I will share more information about Entra Refresh Tokens, Valid for 90 Days – Key Actions Based on Your Licensing.

Patch My PC
Entra Refresh Tokens Valid for 90 Days - Key Actions Based on Your Licensing  Entra ID Free E3 P1 and E5 P2- Fig.1
Entra Refresh Tokens Valid for 90 Days – Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 – Fig.1

Entra Refresh Tokens Valid for 90 Days Key Actions Based on Your Licensing

As mentioned above, you can take specific actions depending on licensing. These measures help improve security and manage access more effectively. The table below shows the specific actions and their details.

Specific ActionsDetails
Entra ID FreeSet directory-level portal time-out
E3 / Entra ID P1Configure sign-in frequency for all admin roles.
E5 / Entra ID P2Enable Privileged Identity Management (PIM) for admin roles and enable risk-based Conditional Access.
Entra Refresh Tokens Valid for 90 Days – Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 – Table.1

Entra ID Free – Directory Level Portal Time Out

Users with the Global Administrator role can enforce the maximum idle time before a session is signed out. This inactivity timeout setting applies to all users in the Azure tenant; Global Administrators can’t specify different settings for individual users in the tenant. Follow the list to enforce an idle timeout setting for all users of the Azure portal.

  • Login to Azure Portal as Global Administrator Account
  • Select Enable directory level idle timeout.
  • Enter the Hours and Minutes for the maximum time a user can be inactive before their session is automatically signed out.
  • Click on the Apply button.
Entra Refresh Tokens Valid for 90 Days - Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 - Fig.2 - Creds to MS
Entra Refresh Tokens Valid for 90 Days – Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 – Fig.2 – Creds to MS

E3 / Entra ID P1 – Configure a Sign Frequency for All Admin Roles

Entra ID P1 (formerly known as Azure Active Directory P1) is an identity and access management service that provides features like Conditional Access, Identity Protection, and advanced group management.

When combined, Microsoft 365 E3 includes Entra ID P1, offering organizations robust security and identity management capabilities and productivity tools. The following steps are to configure Sign in Frequency for All Admin Roles.

  • Open Microsoft Entra admin center
  • Navigate Protection > Conditional Access > Policies
  • Create New Policy
  • Name – Configure a Sign-in Frequency for All Admin Roles
  • Select users and group
  • Select Cloud apps under targets cloud apps
Entra Refresh Tokens Valid for 90 Days - Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 - Fig.3
Entra Refresh Tokens Valid for 90 Days – Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 – Fig.3

E5 / Entra ID P2 – Enable PIM for Admin Roles

Microsoft 365 E5 includes Entra ID P2, which provides advanced security and identity management features. The following are the steps to enable PIM for Admin Roles.

  • Open Microsoft Entra admin center
    • Navigate to Identity Governance > Privileged Identity Management
  • Go to Roles and Select the Role
Entra Refresh Tokens Valid for 90 Days - Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 - Fig.4
Entra Refresh Tokens Valid for 90 Days – Key Actions Based on Your Licensing Entra ID Free E3 P1 and E5 P2 – Fig.4

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Resource

Manage Azure portal settings and preferences

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Entra

Entra ID SSPR Improves Security with Registered Authentication Methods | Impact on Unregistered Users Starting September 2026

Key Takeaway Entra ID SSPR Improves Security with Registered Authentication Methods! Starting September 7, 2026, Microsoft Entra ID Self-Service Password Reset (SSPR) will require users to verify their identity using explicitly registered authentication methods. Directory-sourced contact information, such as mobile phone numbers, business phone numbers, and alternate email addresses, will no longer be accepted for […]

AC Anoop C Nair 4 min read
Entra

Explicit Forward Proxy in Microsoft Entra Internet Access Helps Secure VDI BYOD and Clientless Browsing

Key Takeaways Explicit Forward Proxy in Microsoft Entra Internet Access! This feature allows organizations to use secure web and AI gateway capabilities without deploying the Global Secure Access client, making it useful for browser-based and lightly managed environments. It works with browsers that support Proxy Auto-Configuration (PAC) files. Since this is a prerelease feature, Microsoft […]

AC Anoop C Nair 3 min read
Cloud

Microsoft Enables Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server

Key Takeaways: Let’s discuss about Microsoft Unlocks Entra Writeback for Cloud-Managed Remote Mailboxes to Help Remove Last Exchange Server. For customers with no remaining dependency on their last Exchange Server, a guide for decommissioning your last Exchange Server. Microsoft announced the Public Preview of Cloud-Managed Remote Mailboxes. Microsoft is excited to share these two new milestones […]

AC Anoop C Nair 3 min read