Microsoft Secure Tech Accelerator
Apr 03 2024, 07:00 AM - 11:00 AM (PDT)
Microsoft Tech Community

New Blog | Public Preview: Strictly Enforce Location Policies with Continuous Access Evaluation

Microsoft

At the recent Microsoft Secure event, we provided an early look at a new feature of conditional access which lets you strictly enforce location policies with continuous access evaluation (CAE), allowing you to rapidly invalidate tokens which violate your IP based location policies. Today, we’re delighted to announce this feature is in public preview.  

 

Previously, in the event of an access token theft, attackers could take advantage of the refresh interval to replay the token, regardless of whether it fell outside the location range permitted by a conditional access policy. With our ability to strictly enforce location policies and CAE, CAE enabled applications like Exchange Online, SharePoint, Teams, and Microsoft Graph can now revoke tokens in near real-time in response to network change events noticed by the app – preventing stolen tokens from being replayed outside the trusted network.  

 

When a client’s access to a resource is blocked due to CAE’s strictly enforce location policies being triggered, the client will be blocked. 

BrittanyCCP_0-1690574592833.png

Read the full blog here: Public Preview: Strictly Enforce Location Policies with Continuous Access Evaluation - Microsoft Com...

1 Reply
How different it is from locations that we define and IP address Conditional access policies