I'm experimenting with Dynamic Access Control with a Windows Server 2012 DC and a Windows 8 client (evaluation edition).
I'm seeing a strange bit of behavior where after updating a user's property in Active Directory, it takes TWO signoff/signon events from the Windows 8 client for the user to have the correct claims information. If I do just one ordinary logoff/logon, that doesn't do it. It needs to be twice, or alternatively a reboot will fix it.
Is that a bug in Win8 that got squashed at some later point? Is there another way to force the signon to Windows 8 to update the claims?