auth.recent_sign_in_required
Break-glass requested more than 10 minutes after the operator's last sign-in (auth_time), or without the Conditional Access authentication context the operator tenant requires (acrs).
| Code | auth.recent_sign_in_required |
|---|---|
| HTTP status | 401 |
| Category | Unauthenticated |
| Arguments | maxAgeSeconds, authenticationContext (nullable) |
Example response
{
"type": "https://docs.test.konsolutelab.uk/errors/auth.recent_sign_in_required",
"title": "…",
"status": 401,
"code": "auth.recent_sign_in_required",
"args": {},
"traceId": "00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01",
"instance": "/api/v1/…"
}Handling it
Branch on code, not on title or the status alone, and log traceId. Codes are stable; new codes may appear, so fall back on the HTTP status for a code you do not know. See Handling errors and the list of codes.