We are implementing Entra ID Identity Protection and want to ensure that when a user account is flagged as "High Risk" (Compromised / Risky Sign-in), their active D365 sessions are terminated immediately.
What is the recommended configuration between Entra ID Conditional Access (Continuous Access Evaluation / CAE vs. Sign-in Frequency) and D365 to enforce near real-time session revocation? How does D365 handle token revocation when CAE triggers, and are there specific session timeout parameters in D365 that must align with Entra policies?

Report
All responses (
Answers (