MC1454234 - Power Platform – New Continuous Access Evaluation (CAE) announcement

Message Center

Published

Aug 13, 2026

Service

Dynamics 365 Apps

Tag

New feature

More information

We are announcing Continuous Access Evaluation (CAE) rollout for user sign-in flows to Dataverse as part of ongoing security enhancements for Power Platform. This change affects interactive user access to Dataverse and relies on Microsoft Entra Conditional Access policies for near real-time session evaluation. This rollout will begin on August 17, 2026, starting with early release environments in GCC. We will progressively expand to the remaining sovereign environments — including GCC, GCC High, DoD, and Mooncake - in a staged manner over the subsequent 4 weeks, following our safe deployment process. Full rollout across sovereign environments is anticipated to complete by mid-September 2026. With this rollout, continuous access evaluation becomes generally available for Dataverse and is enabled by default for all customers.

As noted, Continuous Access Evaluation will be enabled in GCC Early Release environments the week of August 17th enabling customers to use this period to validate their Conditional Access policies. The roll-out will continue with standard sandbox and production environments the week of August 24th. With this update, there is no longer a requirement to submit an enablement request for this feature.

Users are advised to review their user-focused CAE Conditional Access policies to ensure alignment to business and security requirements for their Dataverse applications and no unintentional loss of access.

How does this affect me?
Dataverse user access is transitioning to CAE-enabled authentication, where user sessions are continuously evaluated based on Conditional Access policy signals rather than only at the initial sign-in.

As part of this rollout, user sign-in traffic to Dataverse may originate from managed locations that must be permitted and compliant with your organization’s CAE Conditional Access policies.

Note: This change applies only to interactive user sign-in flows.

Who is Impacted?
Customers with:
  • CAE-enabled Conditional Access policies applied to users.
  • Location-based conditions in user CAE policies.
  • Sign-in frequency, session controls, or risk-based policies for Dataverse users.
What do I need to do to prepare?
Customers should take the following actions for user access scenarios:
  1. Review user-targeted CAE Conditional Access policies
    1. Ensure policies allow Dataverse user traffic from locations which are compliant as per your CAE policies.
    2. Avoid overly restrictive location conditions that could unintentionally block user sessions.
  2. Validate interactive user sign-in scenarios
    1. Test Dataverse access for end users under current CAE policies.
    2. Review the policies enforcing location, device, or risk conditions.
No action is required if existing user CAE policies already permit Dataverse access from managed locations.

Resources:
Continuous access evaluation- Power Platform
Continuous access evaluation in Microsoft Entra - Microsoft Entra ID