Case Study
How Far Could an Attacker Get? Validating Cloud Identity Resilience at MDC Research
MDC Research partnered with ProArch to assess the security of its Microsoft Entra ID–based cloud identity environment against modern identity-driven threats. The key concern was how far an attacker could progress using a compromised low-privilege token, including risks tied to Graph API access, SaaS integrations, and identity controls. ProArch conducted a comprehensive penetration test simulating real-world attack techniques such as token abuse, privilege escalation, and API enumeration. The assessment validated that core controls—like Conditional Access, least-privilege permissions, and device compliance—were effective, while also identifying opportunities to further tighten access governance. The result was increased confidence in the organization’s identity security posture and a clear
