As noted, Continuous Access Evaluation will be enabled in GCC Early Release environments the week of August 17th enabling customers to use this period to validate their Conditional Access policies. The roll-out will continue with standard sandbox and production environments the week of August 24th. With this update, there is no longer a requirement to submit an enablement request for this feature.
Users are advised to review their user-focused CAE Conditional Access policies to ensure alignment to business and security requirements for their Dataverse applications and no unintentional loss of access.
How does this affect me?
Dataverse user access is transitioning to CAE-enabled authentication, where user sessions are continuously evaluated based on Conditional Access policy signals rather than only at the initial sign-in.
As part of this rollout, user sign-in traffic to Dataverse may originate from managed locations that must be permitted and compliant with your organization’s CAE Conditional Access policies.
Note: This change applies only to interactive user sign-in flows.
Who is Impacted?
Customers with:
- CAE-enabled Conditional Access policies applied to users.
- Location-based conditions in user CAE policies.
- Sign-in frequency, session controls, or risk-based policies for Dataverse users.
Customers should take the following actions for user access scenarios:
- Review user-targeted CAE Conditional Access policies
- Ensure policies allow Dataverse user traffic from locations which are compliant as per your CAE policies.
- Avoid overly restrictive location conditions that could unintentionally block user sessions.
- Validate interactive user sign-in scenarios
- Test Dataverse access for end users under current CAE policies.
- Review the policies enforcing location, device, or risk conditions.
Resources:
Continuous access evaluation- Power Platform
Continuous access evaluation in Microsoft Entra - Microsoft Entra ID