Traditionally, OAuth access tokens are valid until they expire, often about an hour. If you disable a user or they change location, an app that already has a token keeps accepting it until expiry. That gap is exactly where an attacker with a stolen token operates. Continuous access evaluation (CAE) closes it by letting resource providers, such as Exchange Online, SharePoint Online, Teams and Microsoft Graph, react to important events in near real time.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.