We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Continuous access evaluation
Continuous access evaluation, UAE

You disabled the account at 09:00. Without CAE, their Outlook kept working until the token expired.

Access tokens are valid for one hour by default, and disabling an account does not reach into a session already holding one. Continuous access evaluation closes that window by letting Exchange, SharePoint and Teams subscribe to critical Entra events and stop honouring tokens in near real time.

Book a CAE readiness reviewSee what it covers
Continuous access evaluation for UAE organisations
  • 5 eventsCritical events evaluated in near real time
  • 15 minutesMaximum observed propagation latency
  • InstantIP location policy enforcement
  • Any tenantCritical event evaluation needs no CA policy
What CAE actually does

Eight things to understand before you rely on it.

CAE is genuinely valuable and it is not a blanket revocation switch. It covers specific events, specific services and specific location conditions, and the parts it does not cover are the parts organisations assume it does.

Critical event evaluation, available in any tenant

Enabling services subscribe to critical Entra events and enforce them near real time. Microsoft is explicit that critical event evaluation does not rely on Conditional Access policies, so it is available in any tenant. That is the half of CAE most organisations already benefit from without having configured anything.

The five events that are evaluated

A user account is deleted or disabled, a password is changed or reset, multifactor authentication is enabled for the user, an administrator explicitly revokes all refresh tokens, and high user risk is detected by Entra ID Protection. That list is finite, and knowing it is finite is the point.

How fast near real time actually is

The goal is near real time, and latency of up to 15 minutes might be observed because of event propagation time. IP location policy enforcement, by contrast, is instant. Those are two different numbers and quoting the wrong one in an incident runbook sets the wrong expectation.

Conditional Access policy evaluation inside the service

Exchange Online, SharePoint Online, Teams and Microsoft Graph can synchronise key Conditional Access policies for evaluation within the service itself. This is what allows access to stop immediately after a network location change rather than at the next token refresh.

Token lifetime becomes long lived on purpose

In CAE-aware sessions the token lifetime increases to long lived, up to 28 hours, because revocation is driven by events rather than by expiry. The configurable token lifetime policy is not honoured for CAE-aware clients. Without CAE-capable clients the default access token lifetime remains one hour.

Only IP-based named locations are visible to CAE

CAE has insight into IP-based named locations only. It does not have insight into MFA trusted IPs or country and region based locations. Where a user comes from one of those, CAE is not enforced after they move, and Entra issues a one-hour token without the instant IP enforcement check.

Guest accounts are not covered

Microsoft states directly that CAE does not support guest user accounts, and that revocation events and IP based Conditional Access policies are not enforced instantaneously for them. For UAE organisations working extensively with partners and contractors, that exclusion needs to be in the risk picture explicitly.

Client support determines whether any of it works

CAE relies on the client understanding a claim challenge, which means bypassing its token cache when a resource provider rejects an unexpired token. That requires up to date clients. On Semi-Annual Enterprise Channel, if DisableADALatopWAMOverride or DisableAADWAM is enabled, CAE is not supported at all.

The limit that surprises large estates

Past 5,000 IP ranges in your location policies, real-time location enforcement stops.

Microsoft documents the threshold precisely: when the sum of all IP ranges specified in location policies exceeds 5,000, CAE cannot enforce the user location change flow in real time.

  • In that state Entra issues a one-hour CAE token instead. CAE continues enforcing all other events and policies besides client location change events, so the position is still stronger than traditional one-hour tokens, but the instant location enforcement you were relying on is gone.
  • This matters for organisations that have accumulated named locations over years, one branch or one supplier at a time. Nobody notices crossing 5,000 because nothing fails, the enforcement simply becomes less immediate. Counting your ranges is a ten minute check that most teams have never done.
  • The related constraint is which location types CAE can see at all. It has insight into IP-based named locations only, not MFA trusted IPs and not country or region conditions. Microsoft is explicit that if you want location policies enforced in real time, use only the IP based condition and configure all addresses including both IPv4 and IPv6.
  • There is also a deliberate exception in the other direction. Where a network topology means Entra sees an allowed egress IP while the resource provider sees a disallowed one, Entra issues a one-hour token that suspends IP checks at the resource. Organisations with stable topologies can remove that behaviour with Strict Location Enforcement, which is in public preview.
Ask us to count your named location ranges
How we approach it

Four things that make CAE work as advertised.

CAE rarely fails. What fails is the expectation attached to it, usually written into an offboarding procedure by somebody who read the marketing summary rather than the limitations section.

We count the IP ranges

When the sum of all IP ranges in location policies exceeds 5,000, CAE cannot enforce the location change flow in real time and Entra issues a one-hour token instead. Nothing errors when you cross that line. Counting is a ten minute check that almost nobody has run, and large estates are frequently over it.

We check which location conditions you actually use

CAE has insight into IP-based named locations only. Country and region conditions and MFA trusted IPs are invisible to it, and where a user comes from one, Entra issues a one-hour token without the instant IP enforcement check. Organisations relying on country blocks for real-time control are relying on something else.

We put the guest gap in writing

CAE does not support guest user accounts, and revocation events and IP based policies are not enforced instantaneously for them. In UAE organisations working heavily with contractors and partner firms, that is a material exclusion, and it belongs in the risk register rather than in a documentation footnote nobody read.

We fix the runbook, not just the configuration

The deliverable people actually use is the offboarding procedure. It should say that critical events propagate in near real time with up to 15 minutes latency, that re-enabling a user takes 15 minutes in SharePoint and Teams and 35 to 40 in Exchange, and that a coauthoring session may persist until the document closes.

How a CAE engagement runs

Four phases across roughly three to four weeks.

CAE is largely a readiness and expectation-setting exercise rather than a build. The value is in knowing precisely what is covered before an incident tests the assumption.
  1. 01
    Week 1

    Establish what is already covered

    Critical event evaluation is available in any tenant, so part of this is already working. The task is establishing which clients are CAE capable, which Office update channel is in use, and whether Web Account Manager has been disabled anywhere.

    • Client versions and CAE capability established
    • Office update channel confirmed per group
    • WAM policy settings checked for CAE-breaking values
    • Current CAE configuration state documented
  2. 02
    Week 2

    Audit the location conditions

    The sum of IP ranges across location policies counted against the 5,000 threshold, and location conditions reviewed for types CAE cannot see. Country and region conditions and MFA trusted IPs are identified because they silently prevent real-time enforcement.

    • Total IP ranges counted against the 5,000 limit
    • Non IP-based location conditions identified
    • IPv4 and IPv6 coverage checked for completeness
    • Network topology reviewed for IP variation exposure
  3. 03
    Week 3

    Configure, migrate and decide on strict enforcement

    CAE is now a Conditional Access session control, and tenants that configured the old settings under Security may need to migrate. Alongside that, a decision on whether the network topology is stable enough for Strict Location Enforcement.

    • CAE configured as a Conditional Access session control
    • Migration completed where legacy settings existed
    • Strict enforcement decision recorded with reasoning
    • Exclusions reviewed and justified
  4. 04
    Week 4

    Update the runbooks with real numbers

    The output that matters most. Offboarding and incident runbooks corrected so they state what actually happens and how quickly, including the guest account exclusion and the delay when re-enabling a user.

    • Offboarding runbook updated with documented timings
    • Incident revocation procedure verified end to end
    • Guest account exclusion recorded as a known gap
    • Service desk briefed on re-enable latency
Where this matters

Six situations where the revocation window is the risk.

The common thread is a moment where access must stop and somebody assumes it already has. That assumption is where the exposure sits, not in the technology.

An organisation offboarding staff at scale

High turnover means the offboarding procedure runs constantly, and any gap in it recurs constantly. Knowing that account disable propagates in near real time with up to 15 minutes latency, and that guests are excluded, turns a vague process into one with defined behaviour.

A regulated firm asked how quickly access can be cut

Supervisors and auditors ask this specifically, and the honest answer has numbers in it. Critical events near real time, IP location enforcement instant, policy and group membership changes up to one day. Producing those figures with the documentation behind them is a far better answer than immediately.

A business with a compromised account incident

Revoking refresh tokens is one of the five critical events, so it propagates near real time to enlightened services. What it does not do is reach guest accounts or non-CAE-capable clients, which is exactly what an incident responder needs to know before declaring containment.

An organisation restricting access by location

Location enforcement is where CAE is strongest and most conditional. It is instant, and only for IP-based named locations, and only below 5,000 total ranges. An estate relying on country conditions for real-time control has a different security model from the one it believes it has.

A provider where a departing clinician retains access

Where access to records must stop at the moment employment does, the gap between disabling an account and sessions ending is a governance question. CAE narrows it substantially, and the coauthoring behaviour and guest exclusion are the two remaining cases that need handling deliberately.

A tenant that configured CAE under the old Security settings

The CAE setting moved into Conditional Access, and tenants that previously enabled it for a subset of users must migrate before they can manage it there. Estates in that state frequently do not realise their configuration is now frozen behind a migration step.

Three positions

What happens when you disable an account.

The right column is what most organisations still describe in their offboarding procedure, and it is not what their tenant does. The middle column is where most actually are without having configured anything.
Account disable revokes sessions
CAE configured and understoodNear real time
Critical events only, by defaultNear real time
Assumed instant, never testedAssumed instant
Location change enforced
CAE configured and understoodInstant
Critical events only, by defaultNot enforced
Assumed instant, never testedAssumed
Token lifetime
CAE configured and understoodUp to 28 hours, event driven
Critical events only, by defaultOne hour
Assumed instant, never testedOne hour
IP range count checked
CAE configured and understoodYes, against 5,000
Critical events only, by defaultNo
Assumed instant, never testedNo
Location condition types reviewed
CAE configured and understoodYes
Critical events only, by defaultNo
Assumed instant, never testedNo
Client capability verified
CAE configured and understoodYes
Critical events only, by defaultUnknown
Assumed instant, never testedUnknown
Guest exclusion known
CAE configured and understoodDocumented
Critical events only, by defaultUnknown
Assumed instant, never testedUnknown
Runbook timings accurate
CAE configured and understoodYes
Critical events only, by defaultPartly
Assumed instant, never testedNo
Re-enable latency understood
CAE configured and understoodYes
Critical events only, by defaultNo
Assumed instant, never testedNo
Revocation tested end to end
CAE configured and understoodYes
Critical events only, by defaultNo
Assumed instant, never testedNo
Feature
CAE configured and understood
Critical events only, by default
Assumed instant, never tested
Account disable revokes sessions
Near real timeNear real timeAssumed instant
Location change enforced
InstantNot enforcedAssumed
Token lifetime
Up to 28 hours, event drivenOne hourOne hour
IP range count checked
Yes, against 5,000NoNo
Location condition types reviewed
YesNoNo
Client capability verified
YesUnknownUnknown
Guest exclusion known
DocumentedUnknownUnknown
Runbook timings accurate
YesPartlyNo
Re-enable latency understood
YesNoNo
Revocation tested end to end
YesNoNo
What happens when

Ten timings worth putting in your runbook.

Incident response depends on knowing how long an action takes to bite. Each of these is documented, and several are considerably longer than teams assume.
Action or conditionDocumented behaviour
Critical event, generalNear real time, up to 15 minutes propagation latency
IP location policy enforcementInstant
Default token lifetime, no CAEOne hour
Token lifetime in a CAE sessionLong lived, up to 28 hours
CA policy or group membership changeUp to one day, optimised to two hours in some cases
Re-enabling a disabled user, SharePoint and TeamsTypically a 15 minute delay
Re-enabling a disabled user, Exchange OnlineTypically a 35 to 40 minute delay
Coauthoring session, with a CA IP policyAccess lost on closing the document or app, or after one hour
Coauthoring, network location policy configuredMaximum coauthoring session lifetime reduced to 15 minutes
Over 5,000 IP ranges in location policiesOne-hour CAE token, no real-time location change enforcement
How an engagement runs

Five steps, and the last one is the deliverable people use.

Configuration is a small part of this. The work that changes outcomes is establishing precisely what is covered and writing it into the procedures that run during an incident.
  1. 1

    Establish the baseline that already exists

    Critical event evaluation does not rely on Conditional Access policies and is available in any tenant, so some of this is working already. Establishing which clients are CAE capable, and what the current configuration state is, tells you what you are adding rather than what you are starting.

  2. 2

    Audit the location conditions and count the ranges

    Total IP ranges counted against the 5,000 threshold, non IP-based conditions identified because CAE cannot see them, and IPv4 and IPv6 coverage confirmed. Microsoft is explicit that real-time location enforcement requires the IP based condition with all addresses configured.

  3. 3

    Review client and channel readiness

    CAE requires clients that understand a claim challenge. Office update channel matters: on Semi-Annual Enterprise Channel, DisableADALatopWAMOverride or DisableAADWAM enabled means CAE is not supported. Microsoft recommends organisations do not disable Web Account Manager.

  4. 4

    Configure as a session control and migrate if needed

    CAE is managed through Conditional Access, and tenants that configured it under the old Security settings for a subset of users must migrate first. Alongside it, a recorded decision on Strict Location Enforcement based on whether the network topology is genuinely stable.

  5. 5

    Rewrite the runbooks with documented numbers

    Offboarding and incident procedures updated to state actual behaviour: near real time with up to 15 minutes latency, instant for IP location, the guest exclusion, the coauthoring behaviour, and the re-enable delays of 15 minutes for SharePoint and Teams and 35 to 40 for Exchange.

Straight answers

What organisations ask about continuous access evaluation.

Part of it is already on. Critical event evaluation does not rely on Conditional Access policies, so it is available in any tenant. Conditional Access policy evaluation inside the service, which is what gives instant location enforcement, is the part that depends on configuration and on the policies you have.

Five: a user account is deleted or disabled, a password is changed or reset, multifactor authentication is enabled for the user, an administrator explicitly revokes all refresh tokens, and high user risk is detected by Entra ID Protection. Note also that SharePoint Online does not support user risk events.

The goal is near real time, and latency of up to 15 minutes might be observed because of event propagation. IP location policy enforcement is instant. Those are separate figures and it is worth quoting the right one, because 15 minutes and instant lead to very different incident procedures.

By design. In CAE-aware sessions the token lifetime increases to long lived, up to 28 hours, because revocation is driven by critical events and policy evaluation rather than by expiry. Microsoft frames this as increasing application stability without affecting security posture.

Not for CAE-aware clients. Microsoft states the configurable token lifetime policy is not honoured for clients negotiating CAE-aware sessions. If you are not using CAE-capable clients, the default access token lifetime remains one hour, changed only if you configured it with the Configurable Token Lifetime feature.

No. Microsoft states directly that CAE does not support guest user accounts, and that revocation events and IP based Conditional Access policies are not enforced instantaneously for them. For organisations working extensively with contractors and partner firms, that exclusion needs to be explicit rather than assumed away.

No. CAE only has insight into IP-based named locations, not country and region based locations or MFA trusted IPs. Where a user comes from one of those, CAE is not enforced after they move and Entra issues a one-hour access token without the instant IP enforcement check.

Effectively yes. When the sum of all IP ranges specified in location policies exceeds 5,000, CAE cannot enforce the user location change flow in real time and Entra issues a one-hour CAE token. All other events and policies continue to be evaluated near real time, so the position is still better than a plain one-hour token.

Because policy and membership changes replicate more slowly than critical events. Microsoft states changes to Conditional Access policies and group membership could take up to one day to be effective, with some optimisation reducing that to two hours. To apply immediately, revoke the user sign-in session.

Coauthoring is the documented exception. When multiple users collaborate on a document simultaneously, CAE might not revoke access immediately on policy change. The user loses access after closing the document, closing the Office app, or after one hour when a Conditional Access IP policy is set.

Yes. A SharePoint administrator configuring a network location policy reduces the maximum lifetime of coauthoring sessions for documents in SharePoint Online and OneDrive to 15 minutes, and it can be adjusted further with the SharePoint Online PowerShell command Set-SPOTenant and the IPAddressWACTokenLifetime parameter.

CAE requires the client to understand a claim challenge so it bypasses its cache when an unexpired token is rejected. Microsoft publishes support tables covering Outlook, Teams, Office and OneDrive across web, Win32, iOS, Android and Mac, and they are not uniform. We check yours against those tables rather than generalising.

Yes, on one channel. On Semi-Annual Enterprise Channel, if DisableADALatopWAMOverride or DisableAADWAM is set to enabled or 1, CAE is not supported. On Current Channel or Monthly Enterprise Channel, CAE is supported whatever the setting. Microsoft recommends organisations do not disable Web Account Manager.

It depends what you configured. The setting moved into Conditional Access. Tenants that explicitly enabled it for all users do not need to migrate. Tenants that enabled it for some users, or that explicitly disabled the preview, do need to migrate before they can manage CAE through Conditional Access.

We scope by tenant complexity and how many location policies exist. The useful free first step: add up the IP ranges across all your named locations and check the total against 5,000. If you are over it, your real-time location enforcement is not doing what you think, and that is worth knowing today.
Readiness check

Fifteen questions to answer about your own tenant.

Most of these take minutes. The ones that take longer are the ones where the answer turns out to be different from what everyone assumed.

Coverage

  • Do we know the five critical events?
    The list is finite.
  • Are guests in scope of our access controls?
    CAE does not support guest accounts.
  • Do we rely on country or region conditions?
    CAE cannot see them.
  • Do we use MFA trusted IPs?
    Also invisible to CAE.
  • Is SharePoint expected to act on user risk?
    It does not support user risk events.

Configuration

  • How many IP ranges across all location policies?
    The threshold is 5,000.
  • Are both IPv4 and IPv6 configured?
    Microsoft says include both.
  • Did we configure CAE under the old Security settings?
    Migration may be needed.
  • Is our topology stable enough for strict enforcement?
    It is in public preview.
  • Are we sending traffic through Global Secure Access?
    It affects source IP visibility.

Clients and process

  • Which Office update channel are we on?
    Semi-Annual has a CAE-breaking case.
  • Has WAM been disabled anywhere?
    Microsoft recommends against it.
  • Does our offboarding runbook state real timings?
    Not assumptions.
  • Does the service desk know the re-enable delay?
    15 min SPO, 35 to 40 min EXO.
  • Have we tested a revocation end to end?
    Once, deliberately.
Related reading

The pages around this one.

Conditional Access

The policy layer CAE enforces inside the service.

Learn more

Entra ID Protection

Where the high user risk critical event comes from.

Learn more

Emergency access accounts

The accounts that must survive a revocation event.

Learn more
Next step

Add up the IP ranges across every named location in your tenant.

If the total is over 5,000, CAE cannot enforce location changes in real time and Entra issues a one-hour token instead. Nothing warns you when you cross it, which is precisely why it is worth checking.

Book a CAE readiness reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Token Protection

A stolen token that only works on one device

Learn more

Entra Conditional Access

The control that decides who reaches your data

Learn more

Entra ID Protection

On P1 you see a flag. On P2 you see why, and can act on it

Learn more

Emergency Access Accounts

Break-glass admin that actually works on the day

Learn more

Entra Global Secure Access

Internet Access, Private Access and tenant restrictions

Learn more

Phishing-Resistant MFA

The three methods that actually resist relay attacks

Learn more

Privileged Identity Management

Just-in-time admin access, approval, and audit history you can download

Learn more

Microsoft Entra

Identity and access management solutions

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy