Customers performing tenant-to-tenant migrations using Quest On Demand (Exchange, Teams, SharePoint, and OneDrive) may encounter errors related to token expiration. The error message typically states:
“The provided grant has expired due to it being revoked, a fresh auth token is needed. The user might have changed or reset their password. The grant was issued on (authtime) and the TokensValidFrom date (before which tokens are not valid) for this user is (validate).”
This error occurs after a Global Administrator account, used for granting consents in Quest On Demand, has its password changed. Customers with policies requiring password resets after consent granting may experience repeated token expiration and consent revocation.
This issue arises due to security mechanisms built into Azure Active Directory. When a password change is detected for a Global Administrator account:
To address the issue and ensure a smoother migration process, consider the following suggestions:
Temporary Exemption from Password Reset Policies: