Product tour

EntraGUARD

Audit proves compliance.Simulation proves resilience.

Home / Features / Attack simulation

Read-only Entra ID attack simulation

Replay the paths an attacker would take — read-only, non-intrusive — and see exactly where a chain would succeed.

Attack scenario catalog

Auditing tells you whether a control is compliant. Attack simulation tells you whether an attacker could actually get in. It replays, read-only, the paths an intruder would take against the live tenant — using the same Microsoft Graph access as the audit. No offensive action is performed, no account is touched, no message is sent: each scenario reads the real configuration and decides whether the path would be viable as things stand, and which step would block it.

35 scenarios, three phases

Simulation running with progress radar

Results you can act on

Per-scenario results and KPIs by categorySimulation history with clickable category filters

History & export

Every simulation is kept with its exposure score and viable-path count. The detail repeats the KPIs — clickable to filter the scenarios by category — and exports to the same formats as an audit (CSV, JSON, Excel, HTML, PDF). Native scenarios are built in and cannot be deleted; you can extend the catalog with importable JSON attack packs.

Non-intrusive by design. The simulation only evaluates whether a path would succeed — it never attempts a real sign-in, phishing message or password spray against an account.

Going further in the guide: where simulation fits in the method.