Steps 8 and 9 are skipped when the session already meets the required authentication strength, which covers roughly 71% of sign-ins. Step 15 is the leaver path: revocation reaches CAE-aware resources in about a minute rather than waiting an hour for token expiry.