A cloud-based identity and access management service for securing user authentication and resource access
Hi @Tom Tran (WICLOUD CORPORATION) ,
Thank you for the detailed clarification.
After reviewing your recommendations, I have finalized the following approach for our logout flow:
- RP-initiated logout: I am implementing the standard OIDC RP-initiated logout to ensure that users are signed out through Microsoft Entra ID and all other relying parties (apps) under the same tenant are notified through front-channel logout.
- Session revocation: Post logout, I am calling the Microsoft Graph
/revokeSignInSessionsAPI to invalidate refresh tokens and revoke any active sessions for the user. This helps ensure that future token refreshes are blocked. - User prompt for browser closure: Since certain applications (like Viva Engage) maintain local session data or caches that are not directly cleared via Entra logout, I will display a user prompt recommending the closure of the browser window to complete the logout process cleanly (because I can't clear Viva Engage's cookies).
We have intentionally not reduced the access token lifetime, for the following reasons:
- User Experience: Shorter access token lifetimes would result in frequent re-authentications or background token refresh calls, potentially degrading usability.
- Performance Considerations: Reducing token validity increases network traffic and token issuance volume, which could impact performance and cause throttling under high load.
- Limited Security Benefit: Even with shorter lifetimes, active tokens remain valid until expiration. Therefore, this approach does not provide true real time revocation, unlike CAE and session revocation.
Thank you!