FREE STUDY NOTES · SC-300

Continuous access evaluation (CAE) explained

Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.

From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)

Continuous access evaluation (CAE) lets supporting services reject a still-valid access token when something important changes, instead of waiting up to an hour for it to expire. It’s based on the OpenID Continuous Access Evaluation Profile.

What is evaluated

Scenario Events Needs Conditional Access?
Critical event evaluation User deleted or disabled; password changed or reset; MFA enabled for the user; admin revokes all refresh tokens; high user risk from ID Protection No (any tenant)
Conditional Access policy evaluation IP-based network location changes, enforced by Exchange Online, SharePoint Online, Teams and Microsoft Graph Yes

Common trap: Expecting a country-based named location to be enforced instantly by CAE - CAE only knows IP-range locations. Country and MFA trusted IP locations fall back to one-hour tokens with no instant enforcement.

Get the whole book

This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · SC-300 terms in the glossary · All SC-300 study notes

More SC-300 study notes