Which events and location changes revoke a still-valid token, how long-lived CAE tokens behave, and where CAE falls back to one-hour tokens.
From Ultra Transcenders SC-300 by Tony Rough (coming November 2026)
Continuous access evaluation (CAE) lets supporting services reject a still-valid access token when something important changes, instead of waiting up to an hour for it to expire. It’s based on the OpenID Continuous Access Evaluation Profile.
| Scenario | Events | Needs Conditional Access? |
|---|---|---|
| Critical event evaluation | User deleted or disabled; password changed or reset; MFA enabled for the user; admin revokes all refresh tokens; high user risk from ID Protection | No (any tenant) |
| Conditional Access policy evaluation | IP-based network location changes, enforced by Exchange Online, SharePoint Online, Teams and Microsoft Graph | Yes |
Common trap: Expecting a country-based named location to be enforced instantly by CAE - CAE only knows IP-range locations. Country and MFA trusted IP locations fall back to one-hour tokens with no instant enforcement.
This note is one section of Ultra Transcenders SC-300: Microsoft Identity and Access Administrator, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-300 terms in the glossary · All SC-300 study notes
How the two hybrid sync engines differ in capability and limits, and where each sign-in method checks the password.
The three ways to switch on MFA across a tenant, compared by licence, flexibility and what each one enforces.
What a TAP is for, its lifetime and length settings, and which role can create one for which users.
The difference between the two risk types, real-time versus offline detections, and which detections need P2.
How default and per-organisation settings control B2B collaboration and B2B direct connect, and when MFA and device claims are trusted.
How the two managed identity types differ in lifecycle and sharing, when to choose each, and the Azure roles needed to manage them.
Why every app has a global definition and a per-tenant instance, the three service principal types, and what happens when you change or delete one.