You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
However, from some discussions, it seems that it might be possible to obtain a new refresh token without requiring the user to re-enter their credentials. But I'm not sure I understand. Some people say it's possible, others say it's not.
So, what’s the actual situation? What are the exact configurations on Entra ID and MSAL sides to prevent users from having to re-enter their credentials after 24 hours of inactivity?
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
-
How can I keep a user logged in on a React application with Entra ID authentication after 24 hours of inactivity?
I've searched through the documentation and various forums, but I haven't been able to find a clear answer on this topic.
In the context of a React Single Page Application (SPA), is it possible to keep a user logged in for more than 24 hours?
Specifically, if a user logs in, closes their browser, and returns a week later, will they still be logged in?
According to the documentation, the refresh token in a SPA has a maximum lifetime of 24 hours:
Microsoft Documentation on Refresh Token Lifetime
However, from some discussions, it seems that it might be possible to obtain a new refresh token without requiring the user to re-enter their credentials. But I'm not sure I understand. Some people say it's possible, others say it's not.
So, what’s the actual situation? What are the exact configurations on Entra ID and MSAL sides to prevent users from having to re-enter their credentials after 24 hours of inactivity?
Here is some thread/issues about this subject:
#4944
#2934
https://stackoverflow.com/questions/73189871/how-to-get-24h-refresh-tokens-for-mobile-app-with-azure-b2c
https://learn.microsoft.com/en-us/answers/questions/1293384/msal-expiration-after-a-day?cid=kerryherger
https://www.reddit.com/r/dotnet/comments/1awottr/anyone_with_experience_of_msal_azure_b2c_im/
Beta Was this translation helpful? Give feedback.
All reactions