Tools / Microsoft Threat Modeling Tool (TMT) Interview questions
How is a mitigation documented for a threat in TMT?
In the Analysis view, you open the specific threat entry and use its free-text Justification field to describe the compensating control or fix that addresses it, then update the State to Mitigated (or leave it at Needs Investigation while work is pending).
That text is carried verbatim into the generated report, so it becomes the documented record a reviewer or auditor reads later. TMT has no built-in link to an external ticketing system, so in practice many teams paste a Jira or Azure DevOps work item ID directly into the justification text as a manual cross-reference back to where the actual remediation work was tracked.
More Related questions...