entra1-4 Exercise 1: Credential or Token? ========================================== Source for the lifetimes: Microsoft Learn pages on access tokens, refresh tokens, the authorization code flow, adding app credentials, and managing federation certificates. Defaults can change; re-check before quoting to a client. (a) A client secret Kind: Credential. Lasts: Up to 24 months (Microsoft recommends under 12). Renewed by: A person: create a new secret (the value is shown only once), update your system with it, then remove the old one. (b) An access token Kind: Token. Lasts: A random value between 60 and 90 minutes by default (75 on average); the token response's expires_in says how long. Renewed by: Automatically, with a refresh token or by a new request. (c) A SAML signing certificate Kind: Credential (it signs assertions; it is a certificate, not a token). Lasts: By default 3 years; the date can't be edited after saving, so a different date means a new certificate. Renewed by: A person in the client's tenant (create, then "Make certificate active"), and your system must be given the new certificate too. (d) A refresh token for a normal web app Kind: Token (long-lived). Lasts: 90 days by default (24 hours for single-page apps and for email one-time-passcode flows). Renewed by: Replaced automatically each time it is used. If it expires or is revoked, the user (or application) must sign in again. (e) An authorization code Kind: A very short-lived artifact of a sign-in (not a credential). Lasts: About 1 minute. Renewed by: Automatically: each new sign-in issues a new one. (f) A certificate credential on an app registration Kind: Credential. Lasts: The certificate's own validity, subject to any tenant policy that limits maximum certificate lifetime. Renewed by: A person (or automation): upload the new certificate, update your system to use it, check it is the one in use, remove the old. (g) A provisioning credential issued by your system Kind: Credential. Lasts: Whatever you decided when you issued it. Renewed by: You issue the replacement; the client's administrator enters it in the provisioning settings. Until then, Entra's calls fail and the job can go into quarantine. THE PATTERN ----------- Everything that renews itself is a token (or a code); everything that needs a person to renew it is a credential. A credential's expiry is the one that produces a sudden failure for everyone at once. WHY THIS WORKS AS AN ANSWER --------------------------- It sorts each item by who has to act, which is the question that decides who you contact. It also keeps the defaults and the reason they matter together.