Pro User
Timespan
explore our new search
​
Microsoft Entra Setting Threatens M365
Microsoft Entra
Sep 14, 2025 6:15 PM

Microsoft Entra Setting Threatens M365

by HubSite 365 about Jonathan Edwards

No-Faffing Managed IT Support & Cyber Security Support. Made in Yorkshire, built for the UK.

MS Entra Stay signed in risks MS three sixty five; expert: tokens exposed, disable prompt, enforce Conditional Access

Key insights

  • Video summary: A security-focused YouTube video shows how the small "Stay signed in?" box on the Microsoft 365 sign-in page can expose business accounts and demonstrates a quick fix in the Entra admin center.
  • Token basics: access tokens grant short-lived access, refresh tokens renew sessions, and persistent cookies keep users signed in — attackers who steal these can bypass normal protections.
  • Entra changes: Microsoft’s Secure by Default updates block legacy authentication and limit device code flow, while adding Microsoft-managed Conditional Access and an Admin Consent workflow to reduce abuse of third-party apps.
  • Immediate fix: Disable the "Stay signed in?" prompt in the Entra admin center and set a sign-in frequency policy in Conditional Access to limit persistent sessions and reduce token exposure.
  • Risk explained: Blocking legacy auth and tightening device flows helps stop session hijacking and MFA bypass, threats that let attackers use stolen tokens to impersonate users.
  • Recommended actions: Scan your tenant for legacy protocols, enable the Admin Consent workflow, adopt or customize Microsoft-managed Conditional Access, update Entra Connect, and inform stakeholders about the changes.

Video overview: Stay signed in? prompt

Video overview and why it matters

Jonathan Edwards released a YouTube video that warns administrators about a seemingly small prompt on the sign-in page: the Stay signed in? checkbox for Microsoft 365. In plain language, he explains how that option interacts with tokens and persistent cookies and why it can increase risk for some organizations. Consequently, Edwards frames this as a practical security tip for IT teams, managed service providers, and business owners who manage tenants. Overall, the video aims to help administrators reduce exposure without adding undue complexity.

Importantly, the video also places this prompt in the context of broader changes from Microsoft, such as rollouts that block legacy authentication and changes to admin consent and Conditional Access defaults. Therefore, the guidance is not just about a single checkbox; it relates to how sessions and tokens behave under modern identity controls. As a result, administrators should view the advice as part of a wider tenant hardening strategy. The message is both timely and actionable for those responsible for tenant security.

How tokens, cookies, and the prompt interact

Edwards breaks down the mechanics of access tokens, refresh tokens, and the role of persistent cookies in session persistence. He explains that when users accept the Stay signed in? prompt, clients may receive longer-lived refresh tokens or persistent cookies that let sessions continue across browser restarts. Consequently, attackers who obtain those tokens can sometimes bypass multi-factor protections, which makes token lifetime and storage critical considerations.

Moreover, the video describes how device code flow and legacy protocols can present additional attack surfaces, especially on devices or applications that do not support modern security signals. Thus, while persistent sign-in improves user convenience, it can also extend the window during which a stolen token is valuable. Edwards emphasizes that understanding this tradeoff is the first step toward a balanced security posture.

What Microsoft is changing and the recommended fixes

Edwards highlights Microsoft’s recent moves to make tenants more secure by default, such as blocking legacy authentication and tightening device code scenarios through Conditional Access policies. He then demonstrates a straightforward change in the Microsoft Entra admin center to disable the Stay signed in? prompt, and he shows how to layer a sign-in frequency policy for stronger controls. Consequently, the immediate fix is simple, yet it fits into a larger set of options administrators should consider.

At the same time, Edwards notes that Microsoft also offers managed Conditional Access policies that can automatically apply recommended controls across tenants. Therefore, administrators can either adopt these Microsoft-managed defaults or create tailored policies that reflect their risk tolerance and app ecosystem. Ultimately, the choice involves balancing convenience, compatibility, and the level of manual oversight a team can sustain.

Tradeoffs: convenience, security, and compatibility

The video carefully discusses tradeoffs: disabling persistent sign-in reduces the window for token misuse but increases friction for users who must authenticate more often. In addition, applying aggressive Conditional Access rules may block legacy or unsupported apps, creating service interruptions that require remediation. Thus, organizations must weigh the benefits of reduced risk against potential impacts on productivity and support costs.

Furthermore, Edwards points out that enforcing sign-in frequency and blocking legacy flows requires testing across endpoints, automation, and communication to end users. Consequently, IT teams should plan phased rollouts and maintain fallback options, such as app-based authentication or managed devices that meet policy requirements. This staged approach helps avoid unintended lockouts while improving overall security posture.

Practical steps for administrators

For practical next steps, Edwards urges administrators to inventory where legacy authentication or device code flows remain in use and to identify high-risk accounts or applications. Next, he recommends disabling the Stay signed in? prompt when appropriate, and implementing Conditional Access sign-in frequency or risk-based policies to limit token lifetime. In doing so, administrators can reduce attack surfaces while keeping changes predictable and manageable.

Finally, he suggests combining these controls with clear stakeholder communication and monitoring so that any disruptions are caught early and remediated quickly. Therefore, documentation, user training, and a rollback plan are essential parts of any policy change. By balancing technical controls with operational readiness, organizations can strengthen security without creating excessive friction.

Challenges and the path forward

Edwards warns that the main challenges are compatibility and the administrative burden of tuning policies across diverse environments. For example, smaller organizations may lack the resources to test every app or train every user, while larger enterprises face coordination and change-management hurdles. Nonetheless, the video argues that the risk of leaving long-lived tokens in place outweighs the costs when changes are planned carefully.

In conclusion, the video by Jonathan Edwards serves as a concise reminder that small UI choices like the Stay signed in? prompt have measurable security consequences. Ultimately, by combining simple configuration changes with Conditional Access controls and thoughtful rollout plans, administrators can reduce risk while preserving usability. Therefore, teams should treat this as a practical step toward a more resilient identity strategy.

Microsoft Entra - Microsoft Entra Setting Threatens M365

Keywords

Microsoft Entra security, Entra setting risk, Microsoft 365 security vulnerability, Entra ID misconfiguration, Azure AD Entra risk, secure Entra configuration, protect Microsoft 365 Entra, Entra conditional access mistake