M365 Sign-In and Conditional Access Flow Simulator
Walk through the Microsoft 365 sign-in journey from username entry to password validation, MFA challenge selection, device and location checks, and the point where Conditional Access grants or denies access.
Use and source made available for free. Support these projects via https://ko-fi.com/ciaops.
Microsoft recommended controls
Identity / MFA
Device
Conditional Access helps decide whether a token is issued, but it cannot fully stop a bearer token that was already stolen from being replayed elsewhere; token protection narrows that gap by binding tokens to the client/device where the platform supports it.
Session
Guest / Admin
ASD Essential Eight mappings
ADM
DEV
GST
LOC
USR
What-If Parameters
Use these inputs to override scenario assumptions similar to Conditional Access What-If inputs.
Selected Sign-In Outcome
Best-Practice Comparison
Simulated Entra ID Sign-in Log
This mirrors the kind of record Entra ID would keep for the attempt, including result, risk, device, and applied policy context.
Run a scenario to view the raw record.