<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Dealing with PRT Token Limitations for Okta Users
Single Sign-On
Okta Classic Engine
Okta Identity Engine
Overview

This article will address the limitations of Primary Refresh Tokens (PRT) and the recommended solutions for Okta users encountering issues with legacy authentication protocols.

For Microsoft's recommendations on troubleshooting PRT issues, refer to the Microsoft Entra documentation - Microsoft Documentation - Troubleshoot Microsoft Entra hybrid joined devices.

Applies To
  • Issues with Primary Refresh Tokens (PRT)
  • Legacy Authentication Protocols 
  • Windows 10 or newer
  • PC Login
Cause

Primary Refresh Tokens (PRT) rely on the WINLOGON service, a component of Microsoft's authentication architecture. Notably, Entra ID Conditional Access policies do not come into play during the PRT issuance process, which constitutes a limitation impeding the implementation of Multi-Factor Authentication (MFA). Consequently, any issues related to PRT tokens fall under Microsoft's purview, placing them outside Okta's control.

Solution

If experiencing issues with PRT, please contact Microsoft Support for assistance. Okta recommends setting up an App-Level Sign-on Policy that allows only select Custom User Agents for Entra Hybrid-joined machines.

NOTE: PRT is subject to limitations that may affect the preferred authentication method.

 

Related References

Loading
Dealing with PRT Token Limitations for Okta Users