Standard OAuth access tokens remain valid until expiry even after account disable or password reset. CAE closes that exposure window.

Preface

Resource providers traditionally trust issued tokens for their full lifetime without re-checking identity state.

Problem

After remediation starts, attackers can keep using stolen tokens for up to about an hour to exfiltrate data or pivot.

Solution

Align with NIST SP 800-207:

  1. Enable CAE tenant-wide so services listen for critical security events.
  2. Instant session revocation on disable, password reset, or location change outside trusted boundaries.
  3. Strict location enforcement throughout the session, not only at first sign-in.

PowerShell: Check CAE Status

Connect-MgGraph -Scopes "Policy.Read.All"
Get-MgBetaPolicyContinuousAccessEvaluationPolicy | Format-List