Power Platform - New Continuous Access Evaluation (CAE) rollout nearing completion

🚨 The Signal: Continuous Access Evaluation (CAE) for Dataverse user sign-ins is nearing completion. This enhances security by continuously evaluating user sessions against Microsoft Entra Conditional Access policies, improving real-time threat response for Power Platform.

The Impact

Security teams and Entra ID admins are affected, with a risk of service disruption to Dataverse if Conditional Access policies are not updated.

  • Security teams: Risk of misconfigured policies leading to access issues.
  • Entra ID admins: Need to review and potentially update Conditional Access policies.
  • Power Platform users: Potential for temporary access disruption if policies are not aligned.
  • Compliance officers: Improved real-time access control aligns with security frameworks.

The Action

  1. Review existing Microsoft Entra Conditional Access policies targeting Dataverse users, especially those with location, sign-in frequency, or session controls.
  2. Verify that trusted locations defined in Conditional Access policies include all necessary IP ranges for Dataverse access.
  3. Test Conditional Access policies in report-only mode to identify potential access issues before enforcement.
  4. Communicate any planned policy changes or potential access impacts to affected Power Platform users.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Multi-Factor Authentication · ISM: ISM-0109, ISM-0123, ISM-0140, ISM-0974, ISM-1173, ISM-1228, ISM-1401, ISM-1504, ISM-1505, ISM-1679, ISM-1680, ISM-1681, ISM-1682, ISM-1683, ISM-1815, ISM-1819, ISM-1872, ISM-1873, ISM-1874, ISM-1892, ISM-1893, ISM-1894, ISM-1906, ISM-1907