What is a refresh token?¶
A refresh token is a credential that a client returns to the identity platform to request replacement access tokens without repeating the full interactive sign-in. It extends a client's ability to seek access; it is not normally the credential presented directly to the file service or API.
Renewal separates login time from activity time¶
At 08:10 Dave signs in to Northstar Docs. Microsoft Entra issues an access token and a refresh token to the client. The access token expires, but at 12:03 the client presents its refresh token to Entra. Entra confirms that the continuing authority remains acceptable and issues a replacement access token. At 12:05 Microsoft Graph accepts that new access token for a OneDrive file request.
There need not be a password or MFA event at 12:03. The meaningful chain is original authentication → refresh request → replacement access token → resource activity.
The refresh token goes to the identity platform. The replacement access token goes to the protected resource.
Keep the three events distinct¶
| Event | System making the decision | Representative evidence |
|---|---|---|
| Original authentication and consent | Identity provider | Account, methods, client, permissions, result, correlation and time |
| Refresh-token redemption | Identity provider/token endpoint | Client and user context, requested scope, result, policy and replacement issuance |
| Later resource request | Protected API or cloud service | Access-token/request context, application, operation, object, result and time |
A portal may not expose every redemption as a plainly labelled “refresh” event. Provider terminology, retention and logging vary. Preserve the available sign-in, token, application and resource records, then document which joins are explicit and which are inferred from timing and context.
Expiry, revocation and password change are different controls¶
A refresh token can expire or be rejected because of user, administrator, credential or policy changes. The effect of a password change is not universal: it depends on the provider, client type, authentication route and action taken. Do not state that changing a password necessarily ended every session or token.
Likewise, successful renewal shows that the identity platform accepted the client's continuing authority at that point. It does not prove the original user remained at the device, or that the later request was manually initiated. Examine the client installation, local application data, session history and subsequent resource activity.
Treat any recovered refresh token as a sensitive credential. Preserve it securely and do not test it against a live service without lawful authority, an evidential plan and control of the account impact.
Microsoft refresh tokens - checked 2 September 2026
Microsoft describes a refresh token as a credential bound to a user-and-client combination and used at the identity platform to obtain new access and refresh token pairs. It is not tied to one resource in the way an access token's audience is.
Microsoft documents different defaults and revocation effects for different application and credential types. It also says that using a refresh token can return a new refresh token without automatically revoking the old one. Preserve the configuration and guidance applying at the relevant time rather than assuming one universal lifetime.
State the continuing authority precisely¶
Northstar Docs obtained replacement access authority at 12:03 through its existing refresh route, and Microsoft Graph accepted the resulting token for the 12:05 OneDrive request. The sequence explains continued application access without a new visible login. Device and client evidence are required to identify who controlled or initiated that activity.
The point to remember
A refresh token lets a client ask the identity platform for replacement access tokens. Join the original authentication, renewal decision and later resource event before attributing the continued activity.