CAE sessions run tokens for up to 28 hours. The default is one hour. What you get in exchange is revocation when something happens, and Microsoft is specific about what counts: the account is disabled or deleted, the password is changed or reset, MFA gets turned on, an admin revokes refresh tokens, or ID Protection flags the user as high risk. Allow up to 15 minutes for that to propagate. IP location is the only one that applies straight away.