Tools / Microsoft Threat Modeling Tool (TMT) Interview questions
When should you use a custom template instead of the default SDL template?
Reach for a custom template when the default's generic web/cloud stencils don't represent your architecture's real risk profile - for example, an IoT product with firmware and radio interfaces, or a heavily serverless architecture built on managed queues and functions where the generic "process" and "data store" rules miss service-specific risks.
It's also worth building one when a compliance program mandates an org-specific threat catalog, priority scale, or additional tracked properties (like a control-mapping field), or when the same component types recur across many projects and a shared template saves every team from re-describing the same stencils and rules from scratch.
More Related questions...