Entra ID & IdentityHow-To & HardeningRetrospectives

How to Enable Continuous Access Evaluation and Strict Location Enforcement

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2022, written in 2026 with the benefit of hindsight.

Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and Conditional Access settings need deliberate configuration.

Step 1: Check current CAE settings

In the Entra admin center, Conditional Access policies have a Customize continuous access evaluation session control. Review whether any policy disables CAE (it should generally remain enabled).

Step 2: Understand what CAE enforces by default

Critical event evaluation (account disabled, password reset, sessions revoked, user risk) works automatically with supported services and clients.

Step 3: Plan for strict location enforcement

If you use Conditional Access policies based on named locations (trusted IP ranges), strict enforcement makes supporting services check the IP address of every request, not just at sign-in.

Before enabling:

  • Make sure all egress IP addresses — including IPv6, cloud proxies, VPN split tunnels and secure web gateways — are in your named locations.
  • Check sign-in logs for IP address mismatches between Entra ID and the resource provider (CAE workbook and sign-in log details help).

Step 4: Enable strict location enforcement

In the Conditional Access policy that uses location conditions, set the session control Customize continuous access evaluation → Strictly enforce location policies. Pilot with a small group first.

Step 5: Test revocation

Disable a test account while it is signed in to Outlook or Teams and confirm access ends within minutes.

Step 6: Include CAE in incident response

Document that disabling an account and revoking sessions is the first containment step, and that CAE makes it effective quickly for supported apps.

enable continuous access evaluationContinuous Access Evaluation2022

More on this story