How to Enable Continuous Access Evaluation and Strict Location Enforcement
Retrospective: this article looks back at events from January 2022, written in 2026 with the benefit of hindsight.
Continuous Access Evaluation (CAE) lets Entra ID revoke access in near real time. It's on by default for many tenants, but strict location enforcement and Conditional Access settings need deliberate configuration.
Step 1: Check current CAE settings
In the Entra admin center, Conditional Access policies have a Customize continuous access evaluation session control. Review whether any policy disables CAE (it should generally remain enabled).
Step 2: Understand what CAE enforces by default
Critical event evaluation (account disabled, password reset, sessions revoked, user risk) works automatically with supported services and clients.
Step 3: Plan for strict location enforcement
If you use Conditional Access policies based on named locations (trusted IP ranges), strict enforcement makes supporting services check the IP address of every request, not just at sign-in.
Before enabling:
- Make sure all egress IP addresses — including IPv6, cloud proxies, VPN split tunnels and secure web gateways — are in your named locations.
- Check sign-in logs for IP address mismatches between Entra ID and the resource provider (CAE workbook and sign-in log details help).
Step 4: Enable strict location enforcement
In the Conditional Access policy that uses location conditions, set the session control Customize continuous access evaluation → Strictly enforce location policies. Pilot with a small group first.
Step 5: Test revocation
Disable a test account while it is signed in to Outlook or Teams and confirm access ends within minutes.
Step 6: Include CAE in incident response
Document that disabling an account and revoking sessions is the first containment step, and that CAE makes it effective quickly for supported apps.
- Continuous Access Evaluation Arrives (2022): Revoking Sessions in Near Real Time Platform Changes
- CAE Compatibility Checklist for Apps and Clients How-To & Hardening
- CIO Brief: Why Revoking Access Used to Take an Hour CIO Briefings