Fix Microsoft Graph Attack Simulation 404 Error in Microsoft 365
Question details
The user is unable to successfully download complete Microsoft 365 Attack Simulation data using the Microsoft Graph API and PowerShell due to missing data and error codes.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Attempting to retrieve detailed attack simulation reports and user security coverage data through PowerShell scripting via the Microsoft Graph API.
- Observed behavior
- The simulation report returns limited coverage data, and the security attack simulation command throws a 404 Not Found error despite the account having the AttackSimulation.Read.All permission.
Ensure you have global administrator or security administrator privileges in your Microsoft 365 tenant and that you have granted admin consent to your Microsoft Graph application.
Verify API Endpoints, Version, and Admin Consent
Check that you are using the correct Microsoft Graph API endpoints, the appropriate version, and that the required admin consent has been properly granted for your tenant.
A 404 error typically means the requested endpoint does not exist or has been changed. Attack simulation endpoints can differ significantly between the v1.0 and beta versions of the Microsoft Graph API.
Check your script to see if it is targeting the v1.0 or beta endpoint. Consult the official Microsoft Graph documentation to ensure the attack simulation resource you need is available in that specific version.
Navigate to the Azure Active Directory portal, locate your App Registration under 'App registrations', click on 'API permissions', and ensure that 'AttackSimulation.Read.All' has 'Admin Consent' successfully granted.
Ensure the endpoint URI in your PowerShell command exactly matches the current Microsoft Graph documentation for attack simulation reports to prevent 404 Not Found errors.

Consult Specialized Microsoft Communities
Since this issue involves complex PowerShell scripting and specific Graph API behavior, reaching out to specialized support communities will yield better endpoint troubleshooting.
Try WPS Office as a Lightweight Microsoft Office Alternative
While resolving complex API integrations like Microsoft Graph 404 errors requires dedicated IT troubleshooting, your daily document editing doesn't have to be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for your productivity needs.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the downloaded installer and follow the simple on-screen instructions to set up the software.
- 3. Open Your Documents: Launch WPS Office and directly open your existing Word, Excel, or PowerPoint files without losing any formatting.

Frequently Asked Questions
Why do I get a 404 error in Microsoft Graph despite having correct permissions?
A 404 (Not Found) error typically indicates that the requested endpoint URI is incorrect, the specific resource does not exist in the tenant, or the API version being queried does not support the requested feature, regardless of your assigned permissions.
How do I check if AttackSimulation.Read.All has admin consent?
Log into the Azure Portal, go to Azure Active Directory > App registrations > [Your App] > API permissions. Look for 'AttackSimulation.Read.All' in the list and ensure there is a green checkmark under the 'Status' column indicating admin consent is granted.
Does the Microsoft Graph PowerShell module support all security API endpoints?
Not always. Some newer or specialized security features may require you to use the 'Invoke-MgGraphRequest' cmdlet to call the REST API directly if a dedicated user-friendly cmdlet does not yet exist.
Why is the attack simulation report returning limited user coverage data?
Limited data can occur if the simulation has not fully completed, if pagination (using the @odata.nextLink) is not being properly handled in your API request, or if the calling account lacks access to the full organizational scope.




