Microsoft Certified: Azure Security Engineer AssociateManage identity and accessMedium
A company uses Azure AD for identity management and has several critical applications hosted in Azure. They want to ensure that if a user's account is compromised, the access token issued to that user for these critical applications is immediately revoked, rather than waiting for its normal expiration. Which security feature should be implemented?
- AContinuous Access Evaluation (CAE)
- BAzure AD Identity Protection risk policies
- CAzure AD Privileged Identity Management (PIM)
- DConditional Access session controls
Show answer & explanationAnswer & explanation
Correct answer: A. Continuous Access Evaluation (CAE)
Continuous Access Evaluation (CAE) allows applications to evaluate policy changes and revoke access tokens in near real-time based on critical security events like account compromise or location changes. This directly addresses the need for immediate token revocation.
Why the other options are wrong
- B. Identity Protection risk policies can block sign-ins or require MFA based on risk, but they don't immediately revoke existing access tokens.
- C. PIM manages just-in-time access for privileged roles, not general access token revocation for compromised accounts.
- D. Conditional Access session controls can enforce things like sign-in frequency or persistent browser sessions, but they don't provide immediate token revocation for compromise events.
Continuous Access Evaluation (CAE)
A security standard that enables applications to evaluate policy changes and revoke access tokens in near real-time based on critical security events.
- Immediate token revocation for critical events.
- Reduces the window of opportunity for attackers.
- Requires client applications to support CAE.
Memory trick: CAE is like an instant security camera that can snatch your keys if you're compromised.