Users randomly signed out due to token corruption after password change or session revoke

Fernando Bernardi 0 Reputation points
2025-09-22T17:27:55.9166667+00:00

This issue is related to Microsoft Entra ID (formerly Azure Active Directory) — account object/token-state corruption suspected.

Hi team,

We are facing an issue with ~8 accounts where users keep getting signed out from Microsoft 365 apps (Teams, Outlook, OneDrive, etc.) on all devices (Windows, iOS, and even InPrivate browser sessions).

Symptoms:

  • Error codes: 50133 / 50173 (session not valid due to password change / revoked grant expired).

Even after successful MFA authentication, sessions get terminated shortly after.

Occurs on both compliant corporate devices (Intune-managed) and personal devices.

Troubleshooting done:

Revoked refresh tokens via PowerShell (Revoke-AzureADUserAllRefreshToken).

Disabled and re-enabled MFA methods.

Wiped and re-registered authenticator app.

Cleared cached credentials (Windows Credential Manager, Teams cache, etc.).

Tested on brand-new devices → same issue persists.

Conditional Access reviewed: policies not blocking, MFA strength satisfied.

Observation:

The problem seems linked to account object / token-state corruption in Entra ID.

Affected accounts cannot maintain a stable session, while unaffected accounts in the same tenant work fine.

Workaround: using Microsoft Edge InPrivate window allows temporary access, but apps (Teams/Outlook) still force sign-out later.

Request:

Is this a known issue with Entra ID / token refresh?

What is the recommended escalation path if account object corruption is suspected?

Should we request Microsoft Support to perform a backend reset/reseed of the affected users’ security keys/tokens?

Thanks in advance for any guidance.Hi team,

We are facing an issue with ~8 accounts where users keep getting signed out from Microsoft 365 apps (Teams, Outlook, OneDrive, etc.) on all devices (Windows, iOS, and even InPrivate browser sessions).

Symptoms:

Error codes: 50133 / 50173 (session not valid due to password change / revoked grant expired).

Even after successful MFA authentication, sessions get terminated shortly after.

Occurs on both compliant corporate devices (Intune-managed) and personal devices.

Troubleshooting done:

Revoked refresh tokens via PowerShell (Revoke-AzureADUserAllRefreshToken).

Disabled and re-enabled MFA methods.

Wiped and re-registered authenticator app.

Cleared cached credentials (Windows Credential Manager, Teams cache, etc.).

Tested on brand-new devices → same issue persists.

Conditional Access reviewed: policies not blocking, MFA strength satisfied.

Observation:

The problem seems linked to account object / token-state corruption in Entra ID.

Affected accounts cannot maintain a stable session, while unaffected accounts in the same tenant work fine.

Workaround: using Microsoft Edge InPrivate window allows temporary access, but apps (Teams/Outlook) still force sign-out later.

Request:

Is this a known issue with Entra ID / token refresh?

What is the recommended escalation path if account object corruption is suspected?

Should we request Microsoft Support to perform a backend reset/reseed of the affected users’ security keys/tokens?

Thanks in advance for any guidance.

Azure App Configuration
Azure App Configuration
An Azure service that provides hosted, universal storage for Azure app configurations.
{count} votes

1 answer

Sort by: Most helpful
  1. JimmySalian-2011 44,696 Reputation points
    2025-09-23T09:54:37.5666667+00:00

    Hi Fernando,

    It seems you have a CA Policy that might be setting the validity of the session please review the link I have shared and verify in the CA policy all the settings you have.

    If you have this policy settings, test with few users and exclude or revisit the Policy 1 and policy 2 settings. Please tag me as I am interested to know the outcome and results of this.

    https://free.blessedness.top/en-us/entra/identity/conditional-access/howto-conditional-access-session-lifetime

    Hope this helps.

    JS

    ==

    Please accept as answer and do a Thumbs-up to upvote this response if you are satisfied with the community help. Your upvote will be beneficial for the community users facing similar issues.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.