In AEM when Token Refresh is enabled on the Apache Jackrabbit Oak Token Configuration OSGi configuration, the login token does not refresh. This issue applies to both LDAP, and SAML 2, the default Token authentication.
Login token fails to refresh either due to a misconception of how the token refresh works or if encapsulated token is enabled.
Check if Encapsulated Token Support is enabled. At the time of writing this article (AEM v6.0-6.3), encapsulated token login mechanism did not support token refresh.
If encapsulated token support is not enabled, then it is likely that token refresh is working but it does not work as expected. When users log in, then the token does not refresh unless users access the system after half of the token expiration time configured in the Oak Token Configuration  has passed.
For example, if the expiration is set to two hours, then the user could use the system during the whole first hour. But, if they do not access the system after an hour has passed, then the token would not refresh. Then they have to log in again after two hours have passed from their initial login. However, if they log in, wait for one hour, and access the system again then their token would refresh so the session would be extended.