Read-only Entra ID attack simulation
Replay the paths an attacker would take — read-only, non-intrusive — and see exactly where a chain would succeed.

Auditing tells you whether a control is compliant. Attack simulation tells you whether an attacker could actually get in. It replays, read-only, the paths an intruder would take against the live tenant — using the same Microsoft Graph access as the audit. No offensive action is performed, no account is touched, no message is sent: each scenario reads the real configuration and decides whether the path would be viable as things stand, and which step would block it.
35 scenarios, three phases
- Initial access (8) — AiTM & session theft, device-code phishing, password spraying, legacy auth, MFA fatigue, external IdP, accounts with no MFA, unremediated risky users.
- Persistence & escalation (13) — OAuth consent, shadow admin, break-glass abuse, application / SPN persistence, dormant admins, forged federation (Golden SAML), weak SSPR, permanent TAP, risky app credentials, tenant-takeover Graph permissions, permanent privileged roles, role-assignable groups, privileged guests.
- Configuration & exposure (14) — dangerous app permissions, guest / B2B surface, Conditional Access bypass, cross-tenant abuse, anonymous sharing, ownerless apps, dangerous redirect URIs, permissive user consent, user app creation, no baseline protection, open guest invitations, no admin-consent workflow, no Conditional Access, exploitable dynamic groups.

Results you can act on

- Overall exposure score out of 100
- Count of viable attack paths
- KPIs per attack category — viable paths against the category total
- Per scenario: the question asked, verdict, steps passed or blocked, blocking point and recommendations
- Premium-gated checks are marked "Not assessed — requires an Entra ID Premium licence", never blamed on a missing permission

History & export
Every simulation is kept with its exposure score and viable-path count. The detail repeats the KPIs — clickable to filter the scenarios by category — and exports to the same formats as an audit (CSV, JSON, Excel, HTML, PDF). Native scenarios are built in and cannot be deleted; you can extend the catalog with importable JSON attack packs.
Going further in the guide: where simulation fits in the method.