logo

Primary Refresh Tokens Aren’t Your Parent’s Browser Token

ID: 928ce303-eba6-5ac8-b678-b64fe85fd598

STIX ID: report--928ce303-eba6-5ac8-b678-b64fe85fd598

Feed Name: KnowBe4 Blog

Date Published: 2025-03-04

Date Updated: 2026-04-28

Author: Roger Grimes

...
...

This article explains Microsoft Primary Refresh Tokens (PRTs), how they are issued and stored to enable long-lived single sign-on across Microsoft Entra/Azure AD environments, and why attackers increasingly target them. It outlines common abuse paths—privileged token extraction (e.g., Mimikatz), unauthorized reuse, and device code phishing via platforms like Teams or WhatsApp—and emphasizes that PRTs can bypass conditional access. Recommended mitigations include preventing elevated device access, adopting phishing-resistant authentication, and validating unexpected access or device-approval requests.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.