CIO Brief: Why Revoking Access Used to Take an Hour
Retrospective: this article looks back at events from January 2022, written in 2026 with the benefit of hindsight.
The short version: Until a few years ago, if you disabled a compromised employee account in Microsoft 365, the attacker could keep using it for up to an hour. Microsoft's Continuous Access Evaluation, generally available since 2022, cuts that to minutes for the most important services.
Why speed of revocation matters
When an account is compromised, every minute counts: the attacker may be reading email, downloading files or setting up fraud. Being able to cut off access instantly is a basic incident response capability.
What changed
Microsoft 365 services now listen for important events — an account disabled, a password changed, a sign-in flagged as risky — and immediately reject old access tokens. It works automatically for most organizations using current Microsoft apps.
Questions to ask your team
- If we discovered a compromised account right now, how quickly could we cut off access?
- Have we tested it?
- Are we using location-based rules, and are they enforced continuously or only at sign-in?
- Do our custom applications support instant revocation?
What good looks like
Account disable and session revocation as the first step in incident response, tested regularly, with continuous enforcement for location policies where your network setup allows.
The decision
Ask your team to run a five-minute test: disable a test account while it is signed in and time how long access lasts. It's a quick way to verify a critical capability.
- Continuous Access Evaluation Arrives (2022): Revoking Sessions in Near Real Time Platform Changes
- How to Enable Continuous Access Evaluation and Strict Location Enforcement How-To & Hardening
- CAE Compatibility Checklist for Apps and Clients How-To & Hardening