Ein Azure-Dienst, der eine hybride Multi-Cloud-Verwaltungsplattform für APIs bereitstellt
Hello Eckhart, Johannes,
Thank you for the detailed explanation. Based on the information shared, this behavior is not expected from Microsoft Entra ID for a client credentials–based access token.
An access token issued via the OAuth 2.0 client credentials flow always has a fixed lifetime (typically ~1 hour by default). The values returned in the token response (expires_in, expires_on, and the exp claim in the JWT) reflect the actual token validity and are enforced by Microsoft Entra ID. There is no supported configuration that would cause a token with expires_in: 3599 to remain valid for a week.
Given this, the most likely causes are on the resource/API validation side, not on the token issuance side:
- Token expiration is not being validated by the API The API receiving the token (
baseUrl) must explicitly validate the token’sexpandnbfclaims. If lifetime validation is missing or incomplete, an expired token can still be accepted. This is the most common cause of the behavior you’re seeing. - Audience / resource mismatch The token is requested for
resource=https://management.azure.com/, which means the token’saudis Azure Resource Manager. If the same token is being accepted by a custom API, that indicates the API is not strictly validating theaudclaim, which is a security misconfiguration. - Token lifetime policies / Conditional Access Custom token lifetime policies can change access token lifetime, but only up to 1 day maximum, and Conditional Access / CAE does not allow week‑long validity for app‑only tokens. These settings do not explain a token remaining valid for a week. What to check next
- Decode both the old and new tokens (for example using jwt.ms) and verify:
-
expis already in the past for the one‑week‑old token -
audishttps://management.azure.com/
-
- Review token validation logic on the API side (or API Management policies, if used) and ensure:
- Signature, issuer, audience, and expiration (
exp) are enforced
- Signature, issuer, audience, and expiration (
Confirm the token is actually being presented directly to Azure Resource Manager and not to a custom endpoint that bypasses lifetime validation
Conclusion
Microsoft Entra ID is issuing the token correctly, and the token does expire as stated. If an old token is still accepted, the issue is almost certainly due to missing or incorrect token validation on the resource/API side, not an Entra ID configuration.
Please let us know if you want help reviewing your API token validation setup.