Entra ID & IdentityPlatform ChangesRetrospectives

Continuous Access Evaluation Arrives (2022): Revoking Sessions in Near Real Time

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2022, written in 2026 with the benefit of hindsight.

Continuous Access Evaluation (CAE) changed how quickly Microsoft Entra ID can cut off access. Microsoft announced general availability in early 2022 after a long preview, and enabled it by default for many tenants.

The problem CAE solves

Traditionally, cloud access tokens were valid for about an hour. If an administrator disabled a user, reset a password or detected risk, the user — or an attacker with their token — could keep accessing services like Exchange Online and SharePoint until the token expired.

How CAE works

CAE creates a conversation between Entra ID and supporting services (resource providers). When a critical event occurs — user account disabled or deleted, password changed, sessions revoked, MFA enabled, high user risk detected — Entra ID signals the service, and the service rejects the existing token in near real time, forcing re-authentication.

CAE can also enforce IP location policies: if a token is used from an IP address outside allowed locations, supporting services can reject it immediately.

Because revocation is now possible, CAE-aware clients can receive longer-lived tokens (up to 28 hours) without increasing risk — which also improves resilience during outages.

Supported services

Initially Exchange Online, SharePoint Online and Teams, with support expanding to Microsoft Graph and other services. Clients must be CAE-capable (current Microsoft 365 apps).

In hindsight

CAE is one of those features that works quietly in the background — until an incident. When responders disable a compromised account, CAE is what makes that action take effect in minutes rather than an hour. Strict location enforcement extended the benefit to IP-based policies, though it requires careful network planning to avoid locking users out.

continuous access evaluation2022

More on this story