Skip to content
Skip to main content
Cloud Services Technical Explainer

What is an access token?

An access token is a credential that a client presents to a protected cloud resource or API. It tells that resource what identity or application context is making the request, which audience the token was issued for, which authority was granted and when the token can be accepted.

The token accompanies the resource request

Dave signs in to Northstar's document application. Microsoft Entra issues the application an access token for Microsoft Graph. At 11:16 the application presents that token with a request to read a OneDrive file. Graph validates the token and decides whether the requested operation falls within its audience and permissions.

The example below shows selected claims as readable evidence fields, not a real token. Do not copy or decode live token strings merely to make an illustration.

Read claims by the question they answer

Claim or record field Investigative question Important limit
Issuer and tenant Which identity system and environment issued the authority? Similar display names do not replace stable identifiers
Audience (aud) Which resource or API should accept the token? A token for one audience should not imply access to every service
Subject/object and application identifiers Which user or application context is represented? The token may be user-delegated or application-only
Scope, roles or permissions Which operations may be requested? Permission is capability; a resource event is needed to show use
Issued, not-before and expiry times When could the token be accepted? A resource may reject it earlier because of policy or revocation
Request or token correlation identifiers Which issuance/sign-in and resource events may join? Test the provider's identifier semantics before treating a match as conclusive

Not every access token is a readable JSON Web Token, and clients should not interpret tokens intended for an API they do not control. Investigative value often comes from provider exports, sign-in events, application identity and downstream resource activity rather than the token string itself.

Token use is not necessarily a new human action

A client may present the same valid access token for several API calls without another visible login. A synchronisation application may act in the background. An application-only token may represent a service principal rather than a user at all.

Join the resource event to the token or request context, then to the cloud session and application/device evidence. A refresh token can explain how later access tokens were obtained after the first one expired.

Microsoft access tokens - checked 2 September 2026

Microsoft says an application presents an access token as a bearer credential to the protected resource, commonly in an HTTP authorization header. Microsoft access-token claims can include audience, tenant, subject/object, application, permissions and time limits; exact claims depend on the token and flow.

Microsoft currently assigns access tokens a variable default lifetime, commonly between 60 and 90 minutes, but configuration and policy can affect acceptance. Record the actual token or provider-event times rather than applying a generic duration to the case.

State authority and use separately

Microsoft Graph accepted an access token representing Dave's Northstar user object and the Northstar Docs application for the 11:16 file-read request. That establishes the technical authority used. It does not by itself prove a fresh login, that Dave operated the client, or that every permission in the token was exercised.

The point to remember

An access token carries scoped authority from an identity system to a protected resource. Read its audience, identity/application, permissions and time context, then join it to the resource event and the client that presented it.

Reference: CLD-028Cloud Services