CA-07: Configure Session Controls
Frequently asked questions about implementing and managing the CA-07 security control in Microsoft 365 and Entra ID.
QWhat is CA-07 (Configure Session Controls)?▼
CA-07 is a security control that long-lived sessions increase the window for session hijacking and token theft. enforcing sign-in frequency limits how long a stolen session token remains valid. It requires that sign-in frequency is enforced for admin sessions (8 hours) and sign-in frequency is enforced for user sessions (24 hours), persistent browser sessions are controlled for sensitive scenarios.
QWhy is Configure Session Controls important for Microsoft 365 security?▼
Long-lived sessions increase the window for session hijacking and token theft. Enforcing sign-in frequency limits how long a stolen session token remains valid.
QHow do I implement CA-07 in my tenant?▼
TrueConfig provides one-click remediation for CA-07. Creates CA policy with session controls in report-only mode
QWhat license do I need for CA-07?▼
This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.
QWhich security baseline includes CA-07?▼
CA-07 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.
5
Questions
1
Related Controls
—
Categorized
Related Resources
Still have questions?
Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.
Start Free Trial