Do you know how authentication works in #AzureAD? The purpose of #authentication is to verify that we really are who we say we are. But how is it possible that our login remains active even if we close the browser? Let's take a look at how tokens work in Azure AD. [1/5]
After a successfully authentication, Azure AD issues a set of #tokens. An access token defaults to one hour and grants the user access to a single resource. If a user accesses multiple resources, they will have multiple access tokens. [2/5]
A refresh token, on the other hand, has essentially unlimited validity and its only purpose is to issue a new access token when the existing one expires, or to issue a new access token for a different resource, giving us a single sign-on (#SSO) experience. [3/5]
So, at first glance, the user sees that they are permanently logged in to all services, but in the background, at least once an hour, an authentication process takes place (can be seen in the Azure AD log) and new tokens are issued. [4/5]
This background process is essential to understand other contexts, for example in the validation of conditional access policies, Continuous Access Evaluation (CAE), but also to protect tokens from misuse in #session#hijacking or #pass-the-token. More on that next time 😊
• • •
Missing some Tweet in this thread? You can try to
force a refresh
#OrganizationalUnits (OU) are a way to assign permissions to only certain parts of the organization in onprem #ActiveDirectory. Very often it is unwanted for admins to have permissions over the entire organization. But how to achieve this in Azure AD? [1/4]
For a long time, this was not possible, and companies wanted some equivalent of OUs. That's why in Azure AD we have #AdministrativeUnits (AU), which is the equivalent of organizational units from Active Directory. [2/4]
Unlike onprem AD, administrative units are not containers that house the objects themselves. They are objects to which we can assign other objects. So, we can create an AU called Czech Republic and put users from the Czech Republic in it and delegate an administrators. [3/4]