Using New Outlook on Windows for professional communication and productivity
Dear @jeremy ken,
Thank you for contacting and for providing the error details. I understand how disruptive it is to be repeatedly signed out of Outlook, and I appreciate your patience while we look into this.
Based on the error message you shared (AADSTS70043), this behavior occurs when Microsoft Outlook attempts to use a refresh token that is no longer valid. When this happens, Outlook cannot silently renew the session and instead prompts you to sign in again, which can result in a repeated sign‑in loop.
This scenario is most commonly related to one or more of the following:
- Sign‑in frequency or session controls configured by your organization (Conditional Access)
- Token invalidation following security changes (such as password or MFA updates)
- Cached Outlook/Office sign‑in data on the device continuing to reuse an expired token
This behavior follows Microsoft’s documented Conditional Access session‑lifetime controls and Microsoft Entra multifactor authentication prompts and session lifetime - Microsoft Entra ID | Micr… apply to all Microsoft 365 workloads that natively support OAuth 2.0, including Exchange Online, SharePoint Online, and Teams
When organizations do not change this control, the Microsoft Entra ID default posture is a rolling 90‑day sign‑in frequency, which defines the maximum uninterrupted access period before requiring new authentication. If your tenant has implemented a shorter interval, either intentionally or inherited from an existing CA policy, refresh requests will be unsuccessful once that period expires. Additionally, Sign‑in Frequency now applies not only to primary authentication but also to multifactor authentication (MFA), meaning users may be prompted to complete MFA as part of the re‑authentication cycle.
In this case, please kindly try these steps below:
Step 1: Fully sign out of Outlook and Office
1.In Outlook, go to Settings > Accounts
2.Sign out of the business account
3.Close all Office apps
This forces Outlook to abandon the existing session and request a new token
Step 2: Clear cached Office identity data
If the issue returns, cached tokens must be removed otherwise Outlook may keep retrying the same invalid refresh token.
1.Close all Office apps
2.Delete the local Office identity cache
- Press Windows + R
- Enter the following path: %localappdata%\Microsoft
- Click OK
- In the Microsoft folder, locate and delete the following folders (if they exist): IdentityCache and OneAuth
3.Restart Outlook and sign in again
Step 3: Remove cached credentials
If sign‑in prompts continue:
- Open Windows Credential Manager
- Remove any saved entries related to Microsoft Office/Outlook
- Restart Outlook and sign in again
If you continue to experience the same behavior after completing the steps above, this may be controlled by organization‑level security policies (such as sign‑in frequency settings). In that case, I recommend contacting your IT administrator and asking them to review any Conditional Access or session policies applied to your account. Your IT admin can identify the specific Conditional Access policy responsible for the enforcement by following these steps:- In Microsoft Entra admin center, access Monitoring & health > Sign‑in logs > User sign‑ins (non‑interactive) and locate an entry showing AADSTS70043 for the affected user. Verify that the resource is Exchange Online (typically shown as Office 365 Exchange Online).
- Identify the user’s most recent successful interactive sign in to the same resource preceding the failure. In that entry, review the Conditional Access tab to see which CA policy or policies applied at the time the session was created, specifically any with Sign‑in Frequency configured. This evaluation identifies the exact policy condition that caused the refresh to be denied.
- If visible, review additional details such as “maximum allowed lifetime” or Conditional Access decision claims, which confirm Sign‑in Frequency enforcement.
If you’re unsure who the Global Admin is within your organization, you can find guidance on locating them here: How do I find my Microsoft 365 admin?
Appreciate your patience and understanding and thank you for your time and cooperation. Please feel free to reply below if you have any update or further concern.
Hop you have a great day!
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.