Microsoft Certified: Azure Security Engineer AssociateManage identity and accessHard

A company is planning to implement a new security measure to protect its Azure AD tenant from advanced attacks like token replay and session hijacking. They want to ensure that access tokens issued by Azure AD are protected even if compromised, by limiting their validity and tying them more closely to the user's session context. Which advanced Azure AD security feature addresses this concern by enabling real-time revocation and re-evaluation of access?

  1. AAzure AD Privileged Identity Management (PIM)
  2. BAzure AD Identity Protection
  3. CAzure AD Connect Health
  4. DContinuous Access Evaluation (CAE)
Show answer & explanation

Correct answer: D. Continuous Access Evaluation (CAE)

Continuous Access Evaluation (CAE) is an advanced security feature in Azure AD that enables real-time enforcement of Conditional Access policies. It allows Azure AD to revoke access tokens immediately upon detecting critical security events (e.g., user password change, account disabled, location change) or policy changes, significantly mitigating the risk of token replay and session hijacking by reducing the window of opportunity for attackers.

Why the other options are wrong

  • A. PIM manages just-in-time access for privileged roles, not the real-time session security of active tokens.
  • B. Azure AD Identity Protection detects risks, but CAE is the mechanism that enables *real-time revocation* based on those risks (or other events).
  • C. Azure AD Connect Health monitors the health of identity infrastructure, not session security.

Continuous Access Evaluation (CAE)

A feature in Azure AD that enables real-time enforcement of Conditional Access policies, allowing immediate revocation of access tokens when critical security events or policy changes occur.

  • Reduces the window of opportunity for token replay and session hijacking.
  • Responds to critical events like password changes, user disablement, or location changes.
  • Works with clients that support CAE (e.g., modern Microsoft 365 apps).

Memory trick: CAE constantly checks the token, revoking it instantly if conditions change.

More Manage identity and access questions