What If Tool

Raymond 120 Reputation points
2025-11-10T23:02:36.6333333+00:00

The What If Tool does not currently work with Custom Security Attributes in Conditional Access policies. It does not read or process rules involving custom security attributes, which can lead to inaccurate results. Both the legacy and preview versions of the What If tool are unable to process these rules.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/what-if-tool

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Answer accepted by question author
  1. Monalisha Jena 3,680 Reputation points Microsoft External Staff Moderator
    2025-11-11T06:28:59.2+00:00

    Hello Raymond,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I will try to guide you in this scenario. The What If tool simulates Conditional Access policy evaluation based on user, device, and session parameters. And Custom Security Attributes are relatively new in Microsoft Entra ID and allow organizations to define custom key-value pairs for users. The tool’s evaluation engine does not parse or apply rules involving these attributes, meaning:

    1. Policies that depend on custom attributes will not be reflected in the simulation.
    2. Both legacy and preview versions share this limitation.

    This is a known gap because the What If tool currently supports only built-in attributes and conditions.

    So, yes you guessed it right as There is no official support for custom security attributes in the What If tool as of today. You must manually validate policies using sign-in logs or test accounts.

    Unfortunately, we do not have this in our roadmap for now as Microsoft has not published an ETA for adding this feature.

    However, you can post your feedback in our Azure feedback portal regarding the feature. 

    https://feedback.azure.com/d365community/forum/22920db1-ad25-ec11-b6e6-000d3a4f0789

    This channel is directly monitored by our PM's. They will look into this request and revert back to you directly with an update on this feature.

    Hope this helps! If it answered your question, please consider clicking Accept Answer and Upvote. This will help us and others in the community as well.

    If you need more info, feel free to ask in the comments. Happy to help!

    Regards,

    Monalisha

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.