Does revoking a user’s sessions invalidate a PRT on an Entra-joined device?

0
0
Asked By MellowCedar47 On

We've seen device-code phishing attacks where an attacker uses an OAuth token to register a rogue device in Entra ID and obtain a Primary Refresh Token (PRT). Because the PRT can support single sign-on across Microsoft services, it seems like this could give the attacker a persistent foothold even after the user clicks "Revoke sessions" or resets their password. Does revoking a user's sessions invalidate the PRT, or does the device need to be disabled or deleted separately?

2 Answers

Answered By NorthPine29 On

Treat this as a token and device compromise rather than just a normal sign-in. Stolen or already-issued tokens can sometimes survive a standard session revocation, so investigate the user’s registered devices and sign-in activity. Remove or disable anything unauthorized, revoke sessions, rotate the password and authentication methods, and review Conditional Access policies to prevent unapproved device registration.

Answered By BrightHarbor82 On

A device is managed separately from the user session. Revoking sessions may not immediately invalidate a PRT held by an otherwise active device. If the device is unauthorized, disable or delete it in Entra, then revoke the user’s sessions, reset the password, and reset MFA as appropriate. Conditional Access should also require compliant or managed devices and restrict who can join devices.

QuietMango6 -

That’s the important distinction: disabling the device should invalidate its PRT, while revoking sessions alone may leave the device trusted and able to continue using its PRT.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.