{"id":4319,"date":"2022-08-26T10:52:13","date_gmt":"2022-08-26T17:52:13","guid":{"rendered":"https:\/\/SUMMALAI.COM\/?p=4319"},"modified":"2022-08-26T10:52:14","modified_gmt":"2022-08-26T17:52:14","slug":"how-to-use-the-what-if-tool-to-troubleshoot-conditional-access-policies-on-azure","status":"publish","type":"post","link":"https:\/\/SUMMALAI.COM\/?p=4319","title":{"rendered":"How to Use the &#8220;What If&#8221; Tool to Troubleshoot Conditional Access Policies on Azure"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\" id=\"use-the-what-if-tool-to-troubleshoot-conditional-access-policies\"><\/h1>\n\n\n\n<p>The&nbsp;<strong>Conditional Access What If policy tool<\/strong>&nbsp;allows you to understand the impact of&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/overview\">Conditional Access<\/a>&nbsp;policies in your environment. Instead of test driving your policies by performing multiple sign-ins manually, this tool enables you to evaluate a simulated sign-in of a user. The simulation estimates the impact this sign-in has on your policies and generates a simulation report.<\/p>\n\n\n\n<p>The&nbsp;<strong>What If<\/strong>&nbsp;tool provides a way to quickly determine the policies that apply to a specific user. You can use the information, for example, if you need to troubleshoot an issue.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.youtube-nocookie.com\/embed\/M_iQVM-3C3E\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.youtube-nocookie.com\/embed\/M_iQVM-3C3E<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"how-it-works\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool#how-it-works\"><\/a>How it works<\/h2>\n\n\n\n<p>In the&nbsp;<strong>Conditional Access What If tool<\/strong>, you first need to configure the conditions of the sign-in scenario you want to simulate. These settings may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>The user you want to test<\/li><li>The cloud apps the user would attempt to access<\/li><li>The conditions under which access to the configured cloud apps is performed<\/li><\/ul>\n\n\n\n<p>The What If tool doesn&#8217;t test for&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/service-dependencies\">Conditional Access service dependencies<\/a>. For example, if you&#8217;re using What If to test a Conditional Access policy for Microsoft Teams, the result doesn&#8217;t take into consideration any policy that would apply to Office 365 Exchange Online, a Conditional Access service dependency for Microsoft Teams.<\/p>\n\n\n\n<p>As a next step, you can initiate a simulation run that evaluates your settings. Only policies that are enabled are part of an evaluation run.<\/p>\n\n\n\n<p>When the evaluation has finished, the tool generates a report of the affected policies. To gather more information about a Conditional Access policy, the&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/howto-conditional-access-insights-reporting\">Conditional Access insights and reporting workbook<\/a>&nbsp;can provide more details about policies in report-only mode and those policies currently enabled.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"running-the-tool\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool#running-the-tool\"><\/a>Running the tool<\/h2>\n\n\n\n<p>You can find the&nbsp;<strong>What If<\/strong>&nbsp;tool in the Azure portal under&nbsp;<strong>Azure Active Directory<\/strong>&nbsp;&gt;&nbsp;<strong>Security<\/strong>&nbsp;&gt;&nbsp;<strong>Conditional Access<\/strong>&nbsp;&gt;&nbsp;<strong>What If<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/portal-showing-location-of-what-if-tool.png#lightbox\"><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/portal-showing-location-of-what-if-tool.png\" alt=\"Screenshot of the Conditional Access - Policies page in the Azure portal. In the toolbar, the What if item is highlighted.\"\/><\/a><\/figure>\n\n\n\n<p>Before you can run the What If tool, you must provide the conditions you want to evaluate.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"conditions\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool#conditions\"><\/a>Conditions<\/h2>\n\n\n\n<p>The only condition you must make is selecting a user or workload identity. All other conditions are optional. For a definition of these conditions, see the article&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/concept-conditional-access-policies\">Building a Conditional Access policy<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/supply-conditions-to-evaluate-in-the-what-if-tool.png#lightbox\"><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/supply-conditions-to-evaluate-in-the-what-if-tool.png\" alt=\"Screenshot of the Azure portal What If page ready for conditions to be entered.\"\/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"evaluation\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool#evaluation\"><\/a>Evaluation<\/h2>\n\n\n\n<p>You start an evaluation by clicking&nbsp;<strong>What If<\/strong>. The evaluation result provides you with a report that consists of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>An indicator whether classic policies exist in your environment.<\/li><li>Policies that will apply to your user or workload identity.<\/li><li>Policies that don&#8217;t apply to your user or workload identity.<\/li><\/ul>\n\n\n\n<p>If&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/policy-migration#classic-policies\">classic policies<\/a>&nbsp;exist for the selected cloud apps, an indicator is presented to you. By clicking the indicator, you&#8217;re redirected to the classic policies page. On the classic policies page, you can migrate a classic policy or just disable it. You can return to your evaluation result by closing this page.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/conditional-access-what-if-evaluation-result-example.png#lightbox\"><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/media\/what-if-tool\/conditional-access-what-if-evaluation-result-example.png\" alt=\"Screenshot of an example of the policy evaluation in the What If tool showing policies that would apply.\"\/><\/a><\/figure>\n\n\n\n<p>On the list of policies that apply, you can also find a list of&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/concept-conditional-access-grant\">grant controls<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/concept-conditional-access-session\">session controls<\/a>&nbsp;that must be satisfied.<\/p>\n\n\n\n<p>On the list of policies that don&#8217;t apply, you can find the reasons why these policies don&#8217;t apply. For each listed policy, the reason represents the first condition that wasn&#8217;t satisfied.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"next-steps\"><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool#next-steps\"><\/a>Next steps<\/h2>\n\n\n\n<ul class=\"wp-block-list\"><li>More information about Conditional Access policy application can be found using the policies report-only mode using\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/howto-conditional-access-insights-reporting\">Conditional Access insights and reporting<\/a>.<\/li><li>If you&#8217;re ready to configure Conditional Access policies for your environment, see the\u00a0<a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/concept-conditional-access-policy-common\">Conditional Access common policies<\/a>.<\/li><\/ul>\n\n\n\n<p>Ref: https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/conditional-access\/what-if-tool<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The&nbsp;Conditional Access What If policy tool&nbsp;allows you to understand the impact of&nbsp;Conditional Access&nbsp;policies in your environment. Instead of test driving your policies by performing multiple sign-ins manually, this tool enables you to evaluate a simulated sign-in of a user. The simulation estimates the impact this sign-in has on your policies and generates a simulation report. <a class=\"read-more\" href=\"https:\/\/SUMMALAI.COM\/?p=4319\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[238,239],"tags":[1293,1291,1292],"class_list":["post-4319","post","type-post","status-publish","format-standard","hentry","category-cloud","category-azure","tag-troubleshoot-conditional-access-policies-on-azure","tag-what-if-azure","tag-what-if-conditional-access-policies-on-azure"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4319"}],"version-history":[{"count":1,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4319\/revisions"}],"predecessor-version":[{"id":4320,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=\/wp\/v2\/posts\/4319\/revisions\/4320"}],"wp:attachment":[{"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/SUMMALAI.COM\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}