Continuous Access Evaluation in Azure AD is now generally available!

Published Jan 10 2022 09:13 AM 20.7K Views

Howdy folks,

 

We’re thrilled to announce the General Availability (GA) of Continuous Access Evaluation (CAE) as part of the overall Azure AD Zero Trust Session Management portfolio!

 

CAE introduces real-time enforcement of account lifecycle events and policies, including:

 

  • Account revocation
  • Account disablement/deletion
  • Password change
  • User location change
  • User risk increase

 

On receiving such events, app sessions are immediately interrupted and users are redirected back to Azure AD to reauthenticate or reevaluate policy. With CAE, we have introduced a new concept of Zero Trust authentication session management that is built on the foundation of Zero Trust principles–Verify Explicitly and Assume Breach. With the Zero Trust approach, the authentication session lifespan now depends on session integrity rather than on a predefined duration. This work is consistent with an industry effort called Shared Signals and Events, and we’re proud to be the first company in the group with a generally available implementation of continuous access!

In fact, we’re so excited about CAE that we auto-enabled it for all tenants. Azure AD Premium 1 customers can make configuration changes or disable CAE in a session blade of Conditional Access


Session blade of CAE for customizing configurationsSession blade of CAE for customizing configurations

 

With this GA, you’ll be more secure and resilient because the real-time enforcement of policies can safely extend session duration. In case of any Azure AD outages, users with CAE sessions can ride out these outages without ever noticing them.

 

“With CAE, gone are the days where we are waiting for the session to be revoked or the user to be reauthenticated for critical services like Exchange Online and SharePoint Online. If we ever had a security incident pop with a user identity, knowing that the token can be revoked instantly, is confidence inspiring. Further, the long default session lifetime with CAE is another benefit we welcome, particularly from the perspective of additional resilience to potential outages.”

-- BRIDGEWATER

CAE has been one of our most popular preview features and has already been deployed successfully by thousands of customers across millions of users. You can learn more about CAE here, including a full list of apps that support CAE today.


As always, we’d love to hear any feedback or suggestions you have. Let us know what you think in the comments below or on the Azure AD feedback forum

 

Best regards,

Alex Simons (Twitter: @alex_a_simons)

Corporate Vice President Program Management

Microsoft Identity Division

 

 

 

Learn more about Microsoft identity:

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-2464398%22%20slang%3D%22en-US%22%3EContinuous%20Access%20Evaluation%20in%20Azure%20AD%20is%20now%20generally%20available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2464398%22%20slang%3D%22en-US%22%3E%3CP%3EHowdy%20folks%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%E2%80%99re%20thrilled%20to%20announce%20the%20General%20Availability%20(GA)%20of%20Continuous%20Access%20Evaluation%20(CAE)%20as%20part%20of%20the%20overall%20Azure%20AD%20Zero%20Trust%20Session%20Management%20portfolio!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECAE%20introduces%20real-time%20enforcement%20of%20account%20lifecycle%20events%20and%20policies%2C%20including%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAccount%20revocation%3C%2FLI%3E%0A%3CLI%3EAccount%20disablement%2Fdeletion%3C%2FLI%3E%0A%3CLI%3EPassword%20change%3C%2FLI%3E%0A%3CLI%3EUser%20location%20change%3C%2FLI%3E%0A%3CLI%3EUser%20risk%20increase%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOn%20receiving%20such%20events%2C%20app%20sessions%20are%20immediately%20interrupted%20and%20users%20are%20redirected%20back%20to%20Azure%20AD%20to%20reauthenticate%20or%20reevaluate%20policy.%20With%20CAE%2C%20we%20have%20introduced%20a%20new%20concept%20of%20Zero%20Trust%20authentication%20session%20management%20that%20is%20built%20on%20the%20foundation%20of%20Zero%20Trust%20principles%E2%80%93Verify%20Explicitly%20and%20Assume%20Breach.%20With%20the%20Zero%20Trust%20approach%2C%20the%20authentication%20session%20lifespan%20now%20depends%20on%20session%20integrity%20rather%20than%20on%20a%20predefined%20duration.%20This%20work%20is%20consistent%20with%20an%20industry%20effort%20called%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fopenid.net%252Fwg%252Fsse%252F%26amp%3Bdata%3D04%257C01%257Cannaba%2540microsoft.com%257C389579fc02894bad97b808d9bf5b1ce9%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637751220609410724%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C3000%26amp%3Bsdata%3DpsJULXEcPMAao%252BbIUj1zlmnDm97TwNPfZznspog2bUI%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EShared%20Signals%20and%20Events%3C%2FA%3E%2C%20and%20we%E2%80%99re%20proud%20to%20be%20the%20first%20company%20in%20the%20group%20with%20a%20generally%20available%20implementation%20of%20continuous%20access!%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3EIn%20fact%2C%20we%E2%80%99re%20so%20excited%20about%20CAE%20that%20we%20auto-enabled%20it%20for%20all%20tenants.%20Azure%20AD%20Premium%201%20customers%20can%20make%20configuration%20changes%20or%20disable%20CAE%20in%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fconcept-conditional-access-session%23customize-continuous-access-evaluation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Esession%20blade%20of%20Conditional%20Access%3C%2FA%3E.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Session%20blade%20of%20CAE%20for%20customizing%20configurations%22%20style%3D%22width%3A%20304px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F337996i7EDA8804A80E2FD4%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22Session%20Blade%20for%20CAE.jpg%22%20alt%3D%22Session%20blade%20of%20CAE%20for%20customizing%20configurations%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESession%20blade%20of%20CAE%20for%20customizing%20configurations%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWith%20this%20GA%2C%20you%E2%80%99ll%20be%20more%20secure%20and%20resilient%20because%20the%20real-time%20enforcement%20of%20policies%20can%20safely%20extend%20session%20duration.%20In%20case%20of%20any%20Azure%20AD%20outages%2C%20users%20with%20CAE%20sessions%20can%20ride%20out%20these%20outages%20without%20ever%20noticing%20them.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22%20text-align%20%3A%20left%3B%20%22%3E%3CEM%3E%E2%80%9CWith%20CAE%2C%20gone%20are%20the%20days%20where%20we%20are%20waiting%20for%20the%20session%20to%20be%20revoked%20or%20the%20user%20to%20be%20reauthenticated%20for%20critical%20services%20like%20Exchange%20Online%20and%20SharePoint%20Online.%20If%20we%20ever%20had%20a%20security%20incident%20pop%20with%20a%20user%20identity%2C%20knowing%20that%20the%20token%20can%20be%20revoked%20instantly%2C%20is%20confidence%20inspiring.%20Further%2C%20the%20long%20default%20session%20lifetime%20with%20CAE%20is%20another%20benefit%20we%20welcome%2C%20particularly%20from%20the%20perspective%20of%20additional%20resilience%20to%20potential%20outages.%E2%80%9D%20%3C%2FEM%3E%3C%2FP%3E%0A%3CP%20style%3D%22%20text-align%20%3A%20right%3B%20%22%3E%3CEM%3E--%20BRIDGEWATER%3C%2FEM%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3ECAE%20has%20been%20one%20of%20our%20most%20popular%20preview%20features%20and%20has%20already%20been%20deployed%20successfully%20by%20thousands%20of%20customers%20across%20millions%20of%20users.%20You%20can%20learn%20more%20about%20CAE%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Ffundamentals%2Fconcept-fundamentals-continuous-access-evaluation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E%2C%20including%20a%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fconcept-continuous-access-evaluation%23critical-event-evaluation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Efull%20list%20of%20apps%20that%20support%20CAE%20today%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3EAs%20always%2C%20we%E2%80%99d%20love%20to%20hear%20any%20feedback%20or%20suggestions%20you%20have.%20Let%20us%20know%20what%20you%20think%20in%20the%20comments%20below%20or%26nbsp%3Bon%26nbsp%3Bthe%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F169401-azure-active-directory%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20AD%20feedback%20forum%3C%2FA%3E.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBest%20regards%2C%3C%2FP%3E%0A%3CP%3EAlex%20Simons%20(Twitter%3A%20%3CA%20href%3D%22https%3A%2F%2Ftwitter.com%2FAlex_A_Simons%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%40alex_a_simons%3C%2FA%3E)%3C%2FP%3E%0A%3CP%3ECorporate%20Vice%20President%20Program%20Management%3C%2FP%3E%0A%3CP%3EMicrosoft%20Identity%20Division%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3ELearn%20more%20about%20Microsoft%20identity%3A%3C%2FEM%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CEM%3ERelated%20Articles%3A%3C%2FEM%3E%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Ffundamentals%2Fconcept-fundamentals-continuous-access-evaluation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%3E%3CEM%3EContinuous%20Access%20Evaluation%3C%2FEM%3E%3C%2FSPAN%3E%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3EReturn%20to%20the%20%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-active-directory-identity%2Fbg-p%2FIdentity%22%20target%3D%22_blank%22%3E%3CEM%3EAzure%20Active%20Directory%20Identity%20blog%20home%3C%2FEM%3E%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3EJoin%20the%20conversation%20on%20%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Ftwitter.com%2Fazuread%2Fstatus%2F1278418103903363074%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%3CEM%3ETwitter%3C%2FEM%3E%3C%2FA%3E%3CEM%3E%20and%20%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Fwww.linkedin.com%2Fshowcase%2Fmicrosoft-security%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%3CEM%3ELinkedIn%3C%2FEM%3E%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3EShare%20product%20suggestions%20on%20the%20%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Ffeedback.azure.com%2Fforums%2F169401-azure-active-directory%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3E%3CEM%3EAzure%20Feedback%20Forum%3C%2FEM%3E%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2464398%22%20slang%3D%22en-US%22%3E%3CP%3EMoving%20towards%20real-time%20policy%20and%20security%20enforcement%20with%20Continuous%20Access%20Evaluation%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Picture1.png%22%20style%3D%22width%3A%20200px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F337990i6E93CC08A432A05B%2Fimage-size%2Fsmall%3Fv%3Dv2%26amp%3Bpx%3D200%22%20role%3D%22button%22%20title%3D%22Picture1.png%22%20alt%3D%22Picture1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3263471%22%20slang%3D%22en-US%22%3ERe%3A%20Continuous%20Access%20Evaluation%20in%20Azure%20AD%20is%20now%20generally%20available!%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3263471%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20having%20issues%20with%20this%20as%20if%20we%20turn%20off%20totally%20(following%20the%20instructions%20that%20all%20cloud%20apps%20must%20be%20selected%20and%20no%20additional%20context%20should%20be%20set%20)%20but%20still%20having%20issues%20with%20mobile%20phones.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22MGabor_0-1647955456023.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F357527i36CCA113102AC665%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22MGabor_0-1647955456023.png%22%20alt%3D%22MGabor_0-1647955456023.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EI%20can%20see%20that%26nbsp%3BPartially%20supported%20the%20mobile%20devices%20but%20not%20sure%20what%20that%20means%20and%20the%20matrix%20also%20a%20bit%20complicated.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20have%20any%20advice%20how%20to%20turn%20this%20off%20fully%3F%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EGabor%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Mar 16 2022 12:14 PM
Updated by:
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE