How Do You Configure Continuous Access Evaluation for App Sign-Ins?
You have a Microsoft Entra tenant. You need to configure continuous access evaluation for app sign-ins and assign the configuration to users that are assigned the Application Administrator role. What should you configure?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you know CAE is delivered as a Conditional Access session control rather than as a standalone setting; the trap is confusing the word 'evaluation' in CAE with 'access review'.
Continuous access evaluation (CAE) for app sign-ins is configured and scoped through a Microsoft Entra Conditional Access policy, including the users assigned the Application Administrator role. This page confirms why the Conditional Access policy is the correct answer and walks through the wrong options.
Picking an access review (B) because the phrase 'access evaluation' sounds like periodic access recertification, when CAE is actually a real-time Conditional Access capability.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Continuous access evaluation in Microsoft Entra is not a separate toggle you configure on an app; it is delivered and scoped through Conditional Access. A Conditional Access policy with the continuous access evaluation session control ("Customize continuous access evaluation") lets you define which users, groups, or directory roles get strict enforcement in near real time. Because the requirement is to assign the configuration to users holding the Application Administrator role, the policy's user assignment is where that role is targeted. CAE then acts on token issuance and refresh events, so critical events such as account disablement or password change are honored quickly. As ProNerd explained, CAE is about "making conditional access checks for token refreshes at the time of expiration" so a disabled user or changed IP is caught promptly.Why the Other Options Are Wrong
A sign-in risk policy (A) is a Conditional Access policy built on Microsoft Entra ID Protection signals, used to require MFA or password change when sign-in risk is detected; it does not contain the continuous access evaluation session control that scopes CAE to the Application Administrator role. An access review (B) is a scheduled recertification of group membership, role assignments, or application access — it is periodic, not an evaluation of live tokens or sign-in sessions, and as the learner Siraf reasoned, "This implies access review to apps" is a keyword-level guess that does not match CAE's real-time behavior. Admin consent settings (D) govern how users and admins consent to application permissions and the admin consent request workflow, which is unrelated to session evaluation or token lifetime.Community Comment Notes
Every recorded vote went to the Conditional Access policy, and YesPlease pointed directly at the Microsoft Learn concept page on continuous access evaluation. klayytech outlined CAE prerequisites and the Conditional Access dependency, though their note that it is "in preview" is outdated — CAE is generally available and always on for Microsoft 365 workloads. jarattdavis summed up the rationale that Conditional Access policies allow enforcement of real-time access decisions, while Siraf's access review pick shows exactly the distractor the exam wants you to avoid. Use these comments as confirmation only; the question wording plus Microsoft's documentation is what settles the answer.Official Reference
Exam Strategy
When a question asks how to configure continuous access evaluation and to scope it to a role, look for the word 'Conditional Access' in the options before anything else. Rule out any option describing periodic review, consent, or risk detection, since those are different features with their own learning paths in the SC-300 skills outline.
Frequently Asked Questions
Why is a sign-in risk policy wrong if it is also a Conditional Access policy?
A sign-in risk policy is Conditional Access driven by Microsoft Entra ID Protection risk signals and triggers MFA or password change; it has no continuous access evaluation session control to scope CAE to Application Administrators.
Why is an access review the wrong answer for continuous access evaluation?
Access reviews are periodic recertifications of group, role, or app access, while CAE evaluates live token and session state in near real time, so a recurring review cannot implement it.
Related Analysis
Practice All SC-300 Questions
Access 80 questions with complete answers and detailed explanations.
View Full SC-300 Practice Test →