Glossary
Token replay
Reuse of a stolen session cookie, refresh token or access token from another device or network, letting an attacker act as the user without signing in again.
Token replay is the use of a stolen authentication artefact (a session cookie, a refresh token or an access token) by someone other than the user it was issued to. Because the token already proves that sign-in and MFA were completed, the attacker gets access without knowing the password or passing MFA.
In Microsoft Entra ID, replay appears in the non-interactive sign-in logs: the same Session ID as the original interactive sign-in, used from a different IP address, network or country. The actions performed with the replayed session carry the same identifier in the Unified Audit Log. Containment requires revoking the user's sessions; a password reset alone does not invalidate issued tokens.