Azure continuous_access_evaluation Mappings

Continuous Access Evaluation (CAE) provides the next level of identity security by terminating active user sessions to a subset of Microsoft services (Exchange and Teams) in real-time on changes such as account disable, password reset, and admin initiated user revocation. CAE aims to improve the response time in situations where a policy setting that applies to a user changes but the user is able to circumvent the new policy setting because their OAuth access token was issued before the policy change. It's typical that security access tokens issued by Azure AD, like OAuth 2.0 access tokens, are valid for an hour. CAE enables the scenario where users lose access to organizational SharePoint Online files, email, calendar, or tasks, and Teams from Microsoft 365 client apps within minutes after critical security events (such as user account is deleted, MFA is enabled for a user, High user risk detected by Azure AD Identity Protection, etc.).

Mappings

Capability ID Capability Description Category Value ATT&CK ID ATT&CK Name
continuous_access_evaluation Continuous Access Evaluation respond minimal T1078 Valid Accounts
continuous_access_evaluation Continuous Access Evaluation respond partial T1078.004 Cloud Accounts