oeltayeb.com · Entra ID Toolkit

Checklist

PRT troubleshooting guide

Based on the article: Primary Refresh Token (PRT) explained: fixing SSO and repeated sign-in prompts · 4 min read

When users on Microsoft Entra joined or hybrid joined Windows devices are asked to sign in again and again in Outlook, Teams or the browser, the Primary Refresh Token (PRT) is the first thing I check. In this post I'll explain what the PRT does, how to read its state, and how to fix the usual reasons it goes missing or stale.

How it works

The PRT is an artifact that Microsoft Entra ID issues to Microsoft's own token brokers so they can get tokens for apps without prompting.

  • Microsoft Entra CloudAP plugin: requests the PRT during Windows sign-in on Entra joined and hybrid joined devices, and caches it.
  • Microsoft Entra WAM plugin: uses the PRT when apps ask Web Account Manager for tokens, and injects it into supported browsers for SSO.
  • Bound to the device. Requests are signed with keys created at device registration, protected by the TPM where available. If those keys become unusable, the PRT can't be used.
  • Long-lived, constantly renewed. A PRT is valid for 90 days and keeps renewing while the device is in use. CloudAP renews it every four hours during Windows sign-in, and WAM can renew it during app token requests.

+4 more points in the full article.

Checklist

  1. 1

    Check the SSO state as the user

    Open a normal, non-elevated prompt in the affected user's session:

    cmd
    dsregcmd /status
  2. 2

    Read the PRT diagnostics

    On Windows 10 21H1 and later, a failed attempt since the last successful update is reported under AzureAdPrt:

    AzureAdPrt               : NO
    AcquirePrtDiagnostics    : PRESENT
    Attempt Status           : 0xc000006d
    Credential Type          : Password
    HTTP status              : 400
    Server Error Code        : invalid_grant
    Server Error Description : AADSTS50126: Error validating credentials due to invalid username or password.

    Combine the attempt status with the server error:

    ErrorLikely causeFix
    AADSTS50126Wrong credentials. On hybrid joined devices with password hash sync, often a new password that hasn't synced yet.Wait for password sync, then sign in with the new password.
    AADSTS50155Device authentication failed: the device is deleted or disabled in Entra ID.Re-enable the device, or re-register it.
    AADSTS50034 / 0xc000005fUser not found, or the UPN suffix isn't a verified domain (such as contoso.local).Sync the user; fix the UPN or configure Alternate Login ID.
    WinHTTP 12002, 12007, 12029, 12030Network or proxy problem reaching Entra ID.Allow the endpoints and let the computer account authenticate to the proxy silently.
  3. 3

    Dig into the AAD event logs

    The CloudAP plugin logs errors to Applications and Services Logs › Microsoft › Windows › AAD › Operational and informational events to the Analytic log beside it. To see the Analytic log, select View › Show Analytic and Debug Logs in Event Viewer, then enable the log.

    • 1006 and 1007 (Analytic): start and end of a PRT acquisition; 1007 holds the final error code.
    • 1081 and 1088 (Operational): server errors from Entra ID or the WS-Trust endpoint.
    • 1022 (Analytic) and 1084 (Operational): the URL being called and the network sub-error.
    • 1144 (Analytic): the UPN that was sent, useful for UPN problems.
    powershell
    Get-WinEvent -LogName "Microsoft-Windows-AAD/Operational" -MaxEvents 100 |
        Where-Object { $_.Id -in 1081, 1084, 1088 } |
        Format-List TimeCreated, Id, Message
  4. 4

    Fix the browser path

    If apps work but the browser keeps prompting, confirm the user is signed in to their Edge profile with the work account, or deploy the Chrome extension or policy and Firefox's WindowsSSO policy through Intune.

Verify

  • dsregcmd /status shows AzureAdPrt : YES, a recent AzureAdPrtUpdateTime and an AzureAdPrtExpiryTime in the future.
  • After a lock and unlock, the update time changes.
  • In the sign-in logs, the user's browser sign-ins show the device ID and join type on the Device info tab, and apps open without prompting.

Tips & gotchas

  • Run dsregcmd /status as the user, not elevated. The SSO State reflects the account running the command, and some user fields can show errors from an elevated prompt.
  • On shared devices, the PRT diagnostics may come from another user's attempt.
  • If DeviceAuthStatus isn't SUCCESS, fix the device first. A deleted or disabled device can't get a PRT.
  • Non-Microsoft credential providers aren't supported for PRT issuance and renewal.
  • A Conditional Access sign-in frequency control forces re-authentication by design, so those prompts aren't a PRT fault.

Microsoft Learn references