The tokens are used for a server side process. We are requesting various scopes including offline_access. The process runs successfully and renews the access token for most users.
However, for a handful of users we have an issue where once the initial access token expires, the refresh token immediately fails with the following exception:
{"error":{"code":"InvalidMsaTicket","message":"ErrorCode: 'PP_E_RPS_REASON_TIMEWINDOW_EXPIRED'. Message: ''","innerError":{"requestId":"some-guid-here","date":"2020-03-24T14:40:17"}}}
From Microsoft documentation, access tokens should be valid for 1 hour and refresh tokens valid for 14 days.
We've had users re-authenticate with the same results.