Microsoft 365 and Entra ID
Microsoft 365 (Exchange Online, SharePoint, Teams, OneDrive) and Entra ID (formerly Azure AD) are the identity and productivity of most companies. They share the same directory as Azure (see Azure Pentesting), so compromising M365 can give access to Azure and vice versa. The vectors combine identity attacks (phishing, spraying, app consent) with abuse of collaboration features.
What’s what
Section titled “What’s what”Entra ID identity directory (users, groups, apps, roles)M365 workloads Exchange Online (mail), SharePoint/OneDrive (files), Teams# key roles: Global Administrator (Entra) = full control of the tenantRecon without credentials
Section titled “Recon without credentials”# does the domain use M365/Entra? and tenant datahttps://login.microsoftonline.com/<domain>/.well-known/openid-configuration# valid-user and tenant enumerationo365spray --validate --domain target.comAADInternals (Get-AADIntLoginInformation, tenant info)# federation: managed or federated? (affects the auth attack)Initial access (identity)
Section titled “Initial access (identity)”# password spraying against M365 endpoints (see ad-spray)o365spray --spray -U users.txt -P 'Summer2025!' --domain target.comMFASweep # which services do NOT require MFA? (MFA gaps)# leaked credentials (recon-personas/HIBP)# illicit consent grant: malicious app requesting permissions -> user consents -> tokensThe absence of MFA on some endpoint (or legacy protocols that bypass it) is the key finding for initial access.
Post-compromise of a user
Section titled “Post-compromise of a user”# access to the victim's mail, files, Teams# mail forwarding rules (stealthy exfiltration / BEC)# search for secrets in mail/SharePoint/OneDrive (passwords, documents)# enumerate the tenant from inside (ROADrecon, AzureHound -> see cloud-azure)# internal phishing (from a legitimate account, higher trust)Escalation and bridge to Azure
Section titled “Escalation and bridge to Azure”# from a user to privileged roles (see cloud-azure):# - app/Service Principal with excessive permissions# - illicit consent -> more users' tokens# - "Privileged Role Administrator" role -> Global Admin# - a Global Admin can elevate to control Azure subscriptionsPersistence
Section titled “Persistence”# forwarding/inbox rules (BEC)# add credentials to a Service Principal / app with permissions# register your own device or MFA method on the victim account# federation backdoors (AADInternals) -> very stealthy, requires Global AdminFor the defense
Section titled “For the defense”- MFA everywhere (Conditional Access), block legacy protocols (basic IMAP/POP/SMTP) that bypass MFA.
- Block user consent to apps; review apps/Service Principals and their permissions.
- PIM for privileged roles; minimum Global Admins; anomalous sign-in alerts.
- Detection: new forwarding rules, consents, impossible sign-ins (Entra ID Protection, Defender for Office/Cloud Apps).
- SPF/DKIM/DMARC (anti-spoofing, see Email Enumeration); anti-phishing training.
Testing checklist
Section titled “Testing checklist”- Does the domain use M365/Entra? tenant info (openid-configuration)
- Enumerate valid users (o365spray/AADInternals)
- Password spraying against M365 (Password Spraying)
- MFASweep: endpoints without MFA / legacy protocols
- Illicit consent grant (malicious app)
- Post-compromise: mail/files/forwarding rules
- Enumerate tenant and escalate to Global Admin (Azure Pentesting)
- Bridge to Azure and persistence