EIDCA-015: CA What-If Simulation for Attack Scenarios
- Platform
- Entra ID / M365
- Category
- Entra ID Conditional Access
- Severity
- Info
- Zero Trust pillar
- Identity (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
The Conditional Access What-If tool allows simulation of sign-in scenarios to validate policy behavior against common attack patterns. Without regular what-if testing, policy misconfigurations or gaps may go undetected until exploited by an attacker.
Recommended value
Quarterly what-if simulations covering common attack scenarios including external attacker, compromised device, and legacy auth attempts
Remediation
Use the Conditional Access What-If tool to simulate sign-in scenarios for common attack patterns such as external MFA bypass, legacy authentication attempts, unmanaged device access, and compromised credential usage. Document the results of each simulation and remediate any policies that fail to block the simulated attack. Incorporate what-if testing into the change management process for all CA policy modifications.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| no-data | Not Assessed |
Framework mappings
- NIST SP 800-53
- CA-8
- MITRE ATT&CK
- T1078.004