<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Dealing with PRT Token Limitations for Okta Users

Single Sign-On
Okta Classic Engine
Okta Identity Engine

Overview

This article will address the limitations of Primary Refresh Tokens (PRT) and the recommended solutions for Okta users encountering issues with legacy authentication protocols.

For Microsoft's recommendations on troubleshooting PRT issues, refer to the Microsoft Entra documentation - Microsoft Documentation - Troubleshoot Microsoft Entra hybrid joined devices.

Applies To

  • Issues with Primary Refresh Tokens (PRT)
  • Legacy Authentication Protocols 
  • Windows 10 or newer
  • PC Login

Cause

Primary Refresh Tokens (PRT) rely on the WINLOGON service, a component of Microsoft's authentication architecture. Notably, Entra ID Conditional Access policies do not come into play during the PRT issuance process, which constitutes a limitation impeding the implementation of Multi-Factor Authentication (MFA). Consequently, any issues related to PRT tokens fall under Microsoft's purview, placing them outside Okta's control.

Solution

If experiencing issues with PRT, please contact Microsoft Support for assistance. Okta recommends setting up an App-Level Sign-on Policy that allows only select Custom User Agents for Entra Hybrid-joined machines.

NOTE: PRT is subject to limitations that may affect the preferred authentication method.

 

Related References

Loading
Okta Support - Dealing with PRT Token Limitations for Okta Users