Part 2 of our series on token theft in Microsoft Entra ID is live, accompanying ERNW White Paper 80. This one puts Continuous Access Evaluation to the test empirically. Of 740 first-party resources we checked for the CAE claim, 33 carried it. Revocation timing ranged from 0 seconds for network-based policies to around 5 minutes at Exchange Online. In exchange for that, CAE tokens may live up to 28 hours rather than the usual 90 minutes. https://insinuator.net/2026/09/token-theft-in-microsoft-entra-id-part-2-of-4-continuous-access-evaluation/ by Niklas Kerner #EntraID #CAE #ZeroTrust #InfoSec