Skip to content
Security
Skill

/auditing-entra-id-with-aadinternals

Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use during an authorized Entra ID/Microsoft 365

From plugin
cybersecurity-skills
28k200 skills
Install
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill auditing-entra-id-with-aadinternals --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/auditing-entra-id-with-aadinternals

Context preview

The summary Claude sees to decide when to auto-load this skill.

Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use during an authorized Entra ID/Microsoft 365

SKILL.md

auditing-entra-id-with-aadinternals.SKILL.md
name: auditing-entra-id-with-aadinternals
description: Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use during an authorized Entra ID/Microsoft 365 red-team assessment to map external attack surface or verify AD FS signing certs resist Golden SAML.
domain: cybersecurity
subdomain: identity-access-management
tags:
- aadinternals
- entra-id
- azure-ad
- saml-token-forgery
- federation-backdoor
- token-manipulation
- adfs
- red-team
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- ID.AM-03
mitre_attack:
- T1606.002

Auditing Entra ID with AADInternals

> **Legal Notice:** This skill is for authorized security testing, red-team engagements, and educational purposes only. AADInternals can forge SAML tokens and install federation backdoors that grant persistent impersonation of any tenant user. Use only against tenants you own or have explicit written authorization (rules of engagement) to test. Unauthorized use violates the Computer Fraud and Abuse Act and equivalent laws.

Overview

AADInternals is the most comprehensive offensive/administrative PowerShell toolkit for Microsoft Entra ID (formerly Azure AD), Azure AD Connect, and Active Directory Federation Services (AD FS), authored by Dr. Nestori Syynimaa (Gerenios / Secureworks). It exposes hundreds of cmdlets (all prefixed `AADInt`) covering unauthenticated outsider reconnaissance, access-token acquisition for every Microsoft API, directory manipulation, AD FS/PTA attacks, and the technique it is most famous for: **federation backdoors** that abuse the `Set-MsolDomainFederationSettings` / `ConvertTo-AADIntBackdoor` path so an attacker who controls a federated domain's `IssuerUri` can mint SAML tokens for arbitrary users — mapping to MITRE ATT&CK **T1606.002 (Forge Web Credentials: SAML Tokens)**, the same class of technique used in the SolarWinds (Golden SAML) intrusions.

The toolkit separates capabilities by required position. `Invoke-AADIntReconAsOutsider` and `Get-AADIntLoginInformation` require no credentials — they query public endpoints (`getuserrealm`, OpenID configuration, autodiscover) to reveal verified domains, tenant ID, federation type, brand, and whether Desktop/Seamless SSO is enabled. With a foothold, `Get-AADIntAccessTokenFor*` cmdlets acquire tokens for Azure AD Graph, Microsoft Graph, Exchange Online, SharePoint, Azure Core Management, and more, optionally caching them so subsequent cmdlets reuse them. With Global Administrator (or a synced AD Connect account), the toolkit can read directory secrets, manipulate users, and establish the federation backdoor.

This skill drives AADInternals through a defensive-validation lens: confirm what an external attacker can learn, what a low-privileged token reaches, and whether federation/AD FS configuration would allow Golden SAML — then produce evidence and hardening recommendations.

When to Use

  • During an authorized Entra ID / Microsoft 365 red-team or assumed-breach assessment
  • To enumerate external attack surface (verified domains, federation type, SSO) before credential attacks
  • To validate that federation and AD FS token-signing certificates are protected against Golden SAML
  • To test token acquisition and replay across Microsoft first-party APIs
  • When building detections (pair with the blue-team Graph-log hunting skill) and you need real AADInternals telemetry

Prerequisites

  • Written authorization covering identity-attack and federation-backdoor testing
  • Windows host with PowerShell 5.1+ (or PowerShell 7 on the supported subset)
  • For backdoor/federation tests: Global Administrator (or equivalent) in the target tenant, in scope per the ROE
  • Install the module from the PowerShell Gallery:
  Install-Module AADInternals -Scope CurrentUser
  Import-Module AADInternals
  # Cross-platform AsOutsider-only reimplementation (no creds) is also available:
  #   https://github.com/synacktiv/AADOutsider-py
  • Familiarity with SAML/WS-Federation, OAuth tokens, and Azure AD Connect

Objectives

  • Perform unauthenticated tenant reconnaissance and enumerate verified domains, tenant ID, and federation type
  • Acquire and cache access tokens for Microsoft first-party APIs
  • Enumerate users/groups/roles with an authenticated token
  • Test the federation backdoor / Golden SAML path in a controlled, authorized manner
  • Document exposure and deliver hardening recommendations (token-signing cert protection, federation monitoring)

MITRE ATT&CK Mapping

| ID | Technique | Application in this skill | |----|-----------|---------------------------| | T1606.002 | Forge Web Credentials: SAML Tokens | `ConvertTo-AADIntBackdoor` + `New-AADIntSAMLToken` forge SAML tokens for arbitrary users via a controlled federation `IssuerUri` (Golden SAML) |

Related techniques: **T1087.004** Account Discovery: Cloud Account (recon), **T1528** Steal Application Access Token (token acquisition), **T1556.007** Modify Authentication Process: Hybrid Identity (federation/PTA backdoors).

Workflow

Step 1: Unauthenticated outsider reconnaissance

No credentials required. Identify verified domains, tenant ID, federation type, brand, and SSO status.

# Full outsider recon for a domain (table output)
Invoke-AADIntReconAsOutsider -DomainName "target.com" | Format-Table

# Login/realm details: federation vs managed, AuthURL, brand
Get-AADIntLoginInformation -Domain "target.com"

# Tenant GUID
Get-AADIntTenantID -Domain "target.com"

Step 2: External user enumeration (optional, noisy)

Validate whether usernames exist via the GetCredentialType / autologon endpoints.

# Supply a list of candidate UPNs to test existence
Invoke-AADIntUserEnumerationAsOutsider -UserName "user1@target.com"
# Or pipe many:
Get-Content .\users.txt | Invoke-AADIntU
Read more
Ships withcybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

Get the whole plugin

Other skills on cybersecurity-skills.