What is an access token?¶
An access token is a credential that a client presents to a protected cloud resource or API. It tells that resource what identity or application context is making the request, which audience the token was issued for, which authority was granted and when the token can be accepted.
The token accompanies the resource request¶
Dave signs in to Northstar's document application. Microsoft Entra issues the application an access token for Microsoft Graph. At 11:16 the application presents that token with a request to read a OneDrive file. Graph validates the token and decides whether the requested operation falls within its audience and permissions.
The example below shows selected claims as readable evidence fields, not a real token. Do not copy or decode live token strings merely to make an illustration.
An access token carries authority to the resource. It is not a transcript of the user's original login.
Read claims by the question they answer¶
| Claim or record field | Investigative question | Important limit |
|---|---|---|
| Issuer and tenant | Which identity system and environment issued the authority? | Similar display names do not replace stable identifiers |
Audience (aud) | Which resource or API should accept the token? | A token for one audience should not imply access to every service |
| Subject/object and application identifiers | Which user or application context is represented? | The token may be user-delegated or application-only |
| Scope, roles or permissions | Which operations may be requested? | Permission is capability; a resource event is needed to show use |
| Issued, not-before and expiry times | When could the token be accepted? | A resource may reject it earlier because of policy or revocation |
| Request or token correlation identifiers | Which issuance/sign-in and resource events may join? | Test the provider's identifier semantics before treating a match as conclusive |
Not every access token is a readable JSON Web Token, and clients should not interpret tokens intended for an API they do not control. Investigative value often comes from provider exports, sign-in events, application identity and downstream resource activity rather than the token string itself.
Token use is not necessarily a new human action¶
A client may present the same valid access token for several API calls without another visible login. A synchronisation application may act in the background. An application-only token may represent a service principal rather than a user at all.
Join the resource event to the token or request context, then to the cloud session and application/device evidence. A refresh token can explain how later access tokens were obtained after the first one expired.
Microsoft access tokens - checked 2 September 2026
Microsoft says an application presents an access token as a bearer credential to the protected resource, commonly in an HTTP authorization header. Microsoft access-token claims can include audience, tenant, subject/object, application, permissions and time limits; exact claims depend on the token and flow.
Microsoft currently assigns access tokens a variable default lifetime, commonly between 60 and 90 minutes, but configuration and policy can affect acceptance. Record the actual token or provider-event times rather than applying a generic duration to the case.
State authority and use separately¶
Microsoft Graph accepted an access token representing Dave's Northstar user object and the Northstar Docs application for the 11:16 file-read request. That establishes the technical authority used. It does not by itself prove a fresh login, that Dave operated the client, or that every permission in the token was exercised.
The point to remember
An access token carries scoped authority from an identity system to a protected resource. Read its audience, identity/application, permissions and time context, then join it to the resource event and the client that presented it.