Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Token replay

Reuse of a stolen session cookie, refresh token or access token from another device or network, letting an attacker act as the user without signing in again.

Token replay is the use of a stolen authentication artefact (a session cookie, a refresh token or an access token) by someone other than the user it was issued to. Because the token already proves that sign-in and MFA were completed, the attacker gets access without knowing the password or passing MFA.

In Microsoft Entra ID, replay appears in the non-interactive sign-in logs: the same Session ID as the original interactive sign-in, used from a different IP address, network or country. The actions performed with the replayed session carry the same identifier in the Unified Audit Log. Containment requires revoking the user's sessions; a password reset alone does not invalidate issued tokens.

See AiTM phishing and token replay detection.