How Do You Configure Continuous Access Evaluation for App Sign-Ins?

Plan, implement, and manage Microsoft Entra Conditional Access
Answer Correct answer: C — Configure a Conditional Access policy with the continuous access evaluation session control scoped to the Application Administrator role.

You have a Microsoft Entra tenant. You need to configure continuous access evaluation for app sign-ins and assign the configuration to users that are assigned the Application Administrator role. What should you configure?

  1. a sign-in risk policy
  2. an access review
  3. a Conditional Access policy Correct Answer
  4. the Admin consent settings

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you know CAE is delivered as a Conditional Access session control rather than as a standalone setting; the trap is confusing the word 'evaluation' in CAE with 'access review'.

Continuous access evaluation (CAE) for app sign-ins is configured and scoped through a Microsoft Entra Conditional Access policy, including the users assigned the Application Administrator role. This page confirms why the Conditional Access policy is the correct answer and walks through the wrong options.

Picking an access review (B) because the phrase 'access evaluation' sounds like periodic access recertification, when CAE is actually a real-time Conditional Access capability.

Community Discussion (6 comments)

dzdz 👍 7 Selected: C
C. a Conditional Access policy To configure continuous access evaluation for app sign-ins and assign the configuration to users that are assigned the Application Administrator role, you should configure a Conditional Access policy. Conditional Access policies in Microsoft Entra allow you to control access to apps and resources based on certain conditions such as user, location, device, and application state. By creating a Conditional Access policy, you can enable continuous access evaluation for app sign-ins and target the policy specifically to users assigned the Application Administrator role. This ensures that the configuration applies only to those users who have the appropriate role.
YesPlease 👍 1 Selected: C
Answer C) A conditional access policy https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-continuous-access-evaluation
ProNerd 👍 1 Selected: C
Continuous Access Evaluation has to do with making conditional access checks for token refreshes at the time of expiration to see if the user has been disabled or changed IP addresses. Conditional Access Policy is the answer.
jarattdavis 👍 1 Selected: C
To configure continuous access evaluation for app sign-ins and assign the configuration to users with the Application Administrator role, you should configure a Conditional Access policy (Option C). Conditional Access policies allow you to enforce real-time access decisions based on user and session risk, which is essential for continuous access evaluation.
klayytech 👍 2 Selected: C
Continuous Access Evaluation (CAE) is a valuable security feature in Azure AD that constantly monitors user access. Here's a breakdown on how to configure CAE: Prerequisites: Microsoft Entra (Azure AD) tenant with Conditional Access enabled. Understanding of your organization's security needs and user risk profiles. Steps: Enable CAE (Preview): CAE is currently in preview. To enable it, navigate to the Azure portal and access the Conditional Access blade. Look for "Preview features" and enable "Continuous Access Evaluation."
Siraf 👍 3
Answer is B: "access evaluation for app sign-ins": This implies access review to apps.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Continuous access evaluation in Microsoft Entra is not a separate toggle you configure on an app; it is delivered and scoped through Conditional Access. A Conditional Access policy with the continuous access evaluation session control ("Customize continuous access evaluation") lets you define which users, groups, or directory roles get strict enforcement in near real time. Because the requirement is to assign the configuration to users holding the Application Administrator role, the policy's user assignment is where that role is targeted. CAE then acts on token issuance and refresh events, so critical events such as account disablement or password change are honored quickly. As ProNerd explained, CAE is about "making conditional access checks for token refreshes at the time of expiration" so a disabled user or changed IP is caught promptly.

Why the Other Options Are Wrong

A sign-in risk policy (A) is a Conditional Access policy built on Microsoft Entra ID Protection signals, used to require MFA or password change when sign-in risk is detected; it does not contain the continuous access evaluation session control that scopes CAE to the Application Administrator role. An access review (B) is a scheduled recertification of group membership, role assignments, or application access — it is periodic, not an evaluation of live tokens or sign-in sessions, and as the learner Siraf reasoned, "This implies access review to apps" is a keyword-level guess that does not match CAE's real-time behavior. Admin consent settings (D) govern how users and admins consent to application permissions and the admin consent request workflow, which is unrelated to session evaluation or token lifetime.

Community Comment Notes

Every recorded vote went to the Conditional Access policy, and YesPlease pointed directly at the Microsoft Learn concept page on continuous access evaluation. klayytech outlined CAE prerequisites and the Conditional Access dependency, though their note that it is "in preview" is outdated — CAE is generally available and always on for Microsoft 365 workloads. jarattdavis summed up the rationale that Conditional Access policies allow enforcement of real-time access decisions, while Siraf's access review pick shows exactly the distractor the exam wants you to avoid. Use these comments as confirmation only; the question wording plus Microsoft's documentation is what settles the answer.

Official Reference

Exam Strategy

When a question asks how to configure continuous access evaluation and to scope it to a role, look for the word 'Conditional Access' in the options before anything else. Rule out any option describing periodic review, consent, or risk detection, since those are different features with their own learning paths in the SC-300 skills outline.

Frequently Asked Questions

Why is a sign-in risk policy wrong if it is also a Conditional Access policy?

A sign-in risk policy is Conditional Access driven by Microsoft Entra ID Protection risk signals and triggers MFA or password change; it has no continuous access evaluation session control to scope CAE to Application Administrators.

Why is an access review the wrong answer for continuous access evaluation?

Access reviews are periodic recertifications of group, role, or app access, while CAE evaluates live token and session state in near real time, so a recurring review cannot implement it.

Related Analysis

Practice All SC-300 Questions

Access 80 questions with complete answers and detailed explanations.

View Full SC-300 Practice Test →

← Back to SC-300 Study Guide