Changing the default token life

htps://social.technet.microsoft.com/Forums/windows/en-US/bebfdeb8-3aab-44af-bf18-d7534808422a/after-password-change-in-ad-outlook-will-not-prompt-to-enter-credentials-for-a-day-or-more?forum=outlook

My question is in regards to the above "solved" issue. We currently use DirSync to synchronize our on-premise AD with Azure, and it seems to take up to 12 hours for Outlook to ask for/recognize the new credentials. I understand that there is a default token life of 10 hours, but is there any way to modify that time at all?

May 26th, 2015 6:13pm

That is an ADFS setting.

To see your current settings for the TokenLifetime use the following PowerShell command:
Get-ADFSRelyingPartyTrust "<Your Trust Name>"

You can alter it via the Set command.

Additionally see:
https://technet.microsoft.com/en-us/library/ee892326.aspx
and
https://technet.microsoft.com/en-us/library/ee892363.aspx

Free Windows Admin Tool Kit Click here and download it now
May 26th, 2015 6:41pm

We don't currently have ADFS set up in our environment. We just use DirSync for same sign on, not single sign on. Is there any sort of setting I can modify to reduce the token life within Exchange online itself?
May 27th, 2015 1:09pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics