The EntraGUARD attack simulator: 35 known attacks, replayed read-only
A compliance score tells you how many controls pass. It does not tell you whether an attacker actually gets in. The EntraGUARD attack simulator answers that second question: it replays 35 known Entra ID & Microsoft 365 attacks against the real tenant, in strictly read-only mode, and reports which paths are viable.
Why a simulator on top of an audit
An audit measures posture control by control. It is precise, defensible, and it is exactly what a framework wants. But a stakeholder rarely asks « how many controls pass »; they ask « can someone break in ». Those are different questions. A tenant can score well on paper and still expose a clean, end-to-end attack path — and a single viable path is what an attacker needs.
The simulator reframes the findings as an attacker would read them. Instead of a list of settings, it walks a kill-chain: initial access, then persistence and escalation, then the configuration weaknesses that widen the blast radius. Each scenario answers one blunt question — « does this path work against this tenant, today? »
Read-only by construction
This is the point that matters most: the simulator performs no action on the tenant. It never sends a phishing prompt, never triggers an MFA push, never creates an object, never changes a setting. Every scenario is evaluated purely from configuration and state read through the same read-only Graph application the audit already uses. What it replays is the reasoning of an attack against the tenant's actual configuration — not the attack itself.
That constraint is what makes the simulator safe to run on a production tenant during business hours, and it is also its honest limitation: where a signal is genuinely not observable read-only, the step is reported as inconclusive rather than guessed.
35 scenarios across three phases
The catalogue is grouped by kill-chain phase, and each attack can be toggled on or off before a run:
| Phase | Examples |
|---|---|
| Initial access | AiTM / session theft, device code phishing, password spray, legacy authentication, MFA fatigue, rogue external identity provider, accounts with no registered MFA, unhandled risky users. |
| Persistence & escalation | Consent phishing, shadow admin, break-glass abuse, service principal credentials, standing privileged roles, role-assignable groups, privileged guests, Golden SAML / federation, risky application credentials, tenant-takeover Graph permissions. |
| Configuration & exposure | Conditional Access bypass, cross-tenant abuse, ownerless applications, dangerous redirect URIs, permissive user consent, user app registration, no baseline protection, open guest invitations, no admin consent workflow, no Conditional Access, exploitable dynamic groups, anonymous SharePoint / OneDrive sharing. |
What a run produces
Selecting the attacks and pressing run replays each scenario in turn — the screen streams them one by one, exactly like the audit does, without freezing the page. Nothing else is shown during the run; when it finishes, the result appears: a global exposure score out of 100 and the number of viable attack paths out of the scenarios run.
Each scenario carries its own verdict — attack path viable, attack interrupted, or inconclusive — an exposure sub-score, and, when the path is broken, the exact break point: the control that stopped it. That last detail is the difference between « you failed this scenario » and « your phishing-resistant MFA is what stopped it, keep it ».
History and reporting
Every run is kept in a dedicated history, filterable by period, each entry showing its score, its viable-path count and its scenario count. Opening a run shows the full kill-chain of every scenario, and the run exports as a branded PDF — the same white-label treatment as the audit reports. The dashboard also surfaces the latest simulation as a card, so the exposure score sits next to the compliance score.
How to read it next to the audit
The two are complementary. The audit is the exhaustive, framework-aligned measurement; the simulator is the attacker's-eye summary that makes the audit land in a meeting. A useful habit: present the exposure score and the viable-path count first, then use the audit to explain why each path is open and what to fix. The break points tell you which existing controls are already doing their job — worth naming, because defence that works is rarely celebrated.
One viable path is the headline. A score of 62/100 is abstract; « 18 viable attack paths, and here is the first one step by step » is not. Lead with the path, use the score as the trend line.