Continuous Access Evaluation (CAE)

Continuous Access Evaluation (CAE) is the ongoing re-evaluation of access already granted during a running session, instead of checking permissions only at login and when tokens are renewed. If the security context changes, access is restricted or terminated in near real time.

Without such a mechanism, an issued access token remains valid until it expires, even if the account has since been locked, the password reset or an elevated risk detected. CAE closes this gap by having identity providers and applications exchange security-relevant events and having the applications react to them, for example with a renewed login or termination of the session. This exchange is standardized across vendors by the Continuous Access Evaluation Profile (CAEP) of the OpenID Foundation, which builds on the Shared Signals Framework.

As a product term, CAE is known above all through Microsoft: in Microsoft Entra ID, Continuous Access Evaluation denotes the implementation of this principle on the basis of CAEP, initially for services such as Exchange Online, SharePoint Online and Teams. Deviating from the generic concept, Microsoft extends the validity of access tokens in CAE-capable sessions to up to 28 hours, because they can be revoked early in the event of critical events. CAE complements Adaptive Authentication (Risk-Based Authentication) with evaluation after login and is a mechanism of Zero Trust.