It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda XDR

Simulating Cloud Security Threats - Conditional Access Policy Block from New Location

  • Last updated on

Rule

Office 365 Conditional Access Policy Block from New Location

Purpose

This alert generates when a Conditional Access Policy blocks user authentication originating in country the user has not previously authenticated from in the last 30 days.

Objective

Verify detection when a Conditional Access Policy blocks a login from a new location.

Test Workflow

ConditionalAccessPolicyBlock.png

How to test

  1. Ensure the test user has a Conditional Access Policy that restricts logins to familiar locations (e.g., specific countries or regions).

  2. Use a VPN service to simulate a login attempt from a a location where the user has not logged in for the last 30 days.

  3. Attempt to log in to the Office 365 account from the VPN endpoint.

  4. A Barracuda XDR alert triggers from the SOC. The alert can be viewed via the Barracuda XDR Security Dashboard.

  5. We request that you reply to the security alert stating that the reported activity was associated with authorized security testing.

  6. The SOC team closes the incident, marking the conclusion of this threat simulation test.