CAE Compatibility Checklist for Apps and Clients
Retrospective: this article looks back at events from January 2022, written in 2026 with the benefit of hindsight.
Use this checklist to confirm your applications and clients work well with Continuous Access Evaluation, especially before enabling strict location enforcement.
Clients
- Microsoft 365 apps (Outlook, Teams, OneDrive, Office) on supported, current versions.
- Mobile apps updated.
- Browsers supported for web access.
- Third-party mail clients identified (may not support CAE).
Services
- Exchange Online, SharePoint Online and Teams in use (CAE-supported).
- Microsoft Graph usage by your own applications reviewed — custom apps need to handle claims challenges to benefit from CAE.
- Line-of-business apps using Entra ID tokens documented.
Network
- All corporate egress IPs (IPv4 and IPv6) in named locations.
- Secure web gateway and proxy egress IPs included.
- VPN split tunneling behavior understood (traffic to Microsoft 365 may bypass VPN).
- Cloud-hosted virtual desktops' egress IPs included.
Testing
- Pilot group defined.
- Account disable test performed and access revoked within minutes.
- Location change test performed (if strict enforcement is enabled).
- Sign-in logs reviewed for CAE-related failures.
Operations
- Help desk briefed on symptoms of location enforcement blocks.
- Incident response runbook updated to use session revocation.
- Named locations reviewed when network changes occur.