Microsoft Entra Global Secure Access
Fundamentals

Learn about Universal Continuous Evaluation

In brief

The documentation now covers preview device signals for deleted, disabled, or noncompliant devices. It also specifies reauthentication through a GSA client notification and tunnel disconnection after two minutes if reauthentication is incomplete.

What Entra admins need to know

Device Compliance and User Risk signals should be paired with their corresponding Conditional Access policies; otherwise, reauthentication is silent and administrators cannot act on the CAE event.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Universal Continuous Access Evaluation

Microsoft Entra ID signals that trigger Universal CAE reauthentication

Global Secure Access is enabled to receive signals from Entra ID in near real-time forUniversal CAE supports the following events:user-based signals:

  • User account is deleted or disabled
  • Password for a user is changed or reset
  • Administrator explicitly revokes all refresh tokens for a user
  • High user risk detected by Microsoft Entra ID Protection

Universal CAE supports the following device-based signals (preview):

  • Device from which GSA access is being performed is deleted or disabled
  • Device from which GSA access is being performed is detected to be in the non-compliant state

When Global Secure Access receives the security event, the client promptsuser is required to re-authenticate via a notification toast in the user to reauthenticate.GSA client. If the user successfully reauthenticates, the user'sis not re-authenticated within 2 minutes, all GSA tunnels are disconnected and network connectivity to resources protected by Global Secure Accessapplications is restored.dropped. Connectivity is restored upon successful re-authentication.

Strict Enforcement mode

With the Strict Enforcement mode, Universal CAE immediately stops access if the IP address detected by the resource provider isn't allowed by Conditional Access policy. This option is the highest security modality of CAE location enforcement, and requires that administrators understand the routing of authentication and access requests in their network environment. When strict enforcement is enabled, access to the Global Secure Access services is only possible when your users connect to the Global Secure Access service from IP address ranges authorized by your organization.

Strict Enforcement mode

With the Strict Enforcement mode, Universal CAE immediately stops access if the IP address detected by the resource provider isn't allowed by Conditional Access policy. This option is the highest security modality of CAE location enforcement, and requires that administrators understand the routing of authentication and access requests in their network environment. When strict enforcement is enabled, access to the Global Secure Access services is only possible when your users connect to the Global Secure Access service from IP address ranges authorized by your organization.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…