CYYDER CLARITYβ„’ FRAMEWORK | CATEGORY: 🟩 ENTERPRISE & IDENTITY

Lab 5 β€” Identity Attack & Zero Trust Decision Sandbox

Assume the password is already stolen. Decide which Conditional Access controls actually stop the intrusion.

πŸ’Ό Business Scenario: An employee's primary credentials (Username & Password) were leaked in a dark web dump. An external attacker is attempting to log in to the corporate cloud tenant (Microsoft 365 / Entra ID) from a high-risk IP in another country. Can your Zero Trust Conditional Access policies block the breach before data exfiltration occurs?

Context βœ”Landscape βœ”Alignment βœ”Risk & Control βœ”Testing βœ”

Identity Context

Compromised Identity
alex.morgan@company.com
Credentials
Username + Password (Pwned)
Target Service
Enterprise M365 / Salesforce

Attack Simulation Scenario

The attacker replays the leaked username and password against the legacy IMAP endpoint. Basic authentication protocols cannot present an MFA challenge, so modern MFA is silently bypassed.

ProtocolIMAP4 / Basic Auth
ClientMail client (non-interactive)
Source IP45.128.x.x β€” Netherlands VPS
MFA capableNo

Authentication Pipeline

  1. 01

    Primary Auth

    Username + password verification

    β€”
  2. 02

    Risk & Context Engine

    Location, device, reputation, velocity

    β€”
  3. 03

    Conditional Access

    Zero Trust policy enforcement

    β€”
  4. 04

    Access Result

    Token issued or session denied

    β€”

Zero Trust Policy & Conditional Access Engine

Require Multi-Factor Authentication (MFA)

Challenge a second factor on every interactive sign-in to cloud apps.

Block Legacy Authentication Protocols

Reject IMAP, POP3, SMTP AUTH and other basic-auth clients that cannot perform MFA.

Active controls: 0 / 6

Evaluation Result

Configure your Zero Trust posture, then run the simulation to see whether the attacker reaches your data β€” and which control decides the outcome.

What Should the CISO Ask?

Executive governance checklist β€” take these four questions into your next identity security review.