azure-requirements.md (2343B)
1 --- 2 title: "Azure - Requirements" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-requirements.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-requirements.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure - Requirements 12 13 ## Pentest Requirements 14 15 Users and roles: 16 17 * **Global Reader** and **Security Reader** roles in Azure AD 18 * **Reader** permission over the subscription 19 20 Subscriptions: 21 22 * [Azure Dev/Test](https://azure.microsoft.com/en-us/pricing/offers/dev-test) subscription. 23 * Visual Studio subscription determines the monthly Azure credits you receive 24 * Visual Studio Enterprise: $150/month 25 * MSDN Platforms: $100 26 * Visual Studio Professional: $50 27 * Visual Studio Test Professional: $50 28 29 ## Powershell and Native Modules 30 31 * [Microsoft Graph](https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation?view=graph-powershell-1.0): `Install-Module Microsoft.Graph -Scope CurrentUser` 32 * [Azure AD](https://learn.microsoft.com/fr-fr/powershell/azure/active-directory/install-adv2?view=azureadps-2.0): `Install-Module AzureAD` 33 * [Azure AD Preview](https://learn.microsoft.com/fr-fr/powershell/azure/active-directory/install-adv2?view=azureadps-2.0): `Install-Module AzureADPreview` 34 * [Azure CLI](https://learn.microsoft.com/fr-fr/cli/azure/install-azure-cli-windows?tabs=winget): `winget install -e --id Microsoft.AzureCLI` 35 36 ## Terminology 37 38 * **Tenant**: An instance of Azure AD and represents a single organization. 39 * **Azure AD Directory**: Each tenant has a dedicated Directory. This is used to perform identity and access management functions for resources. 40 * **Subscriptions**: It is used to pay for services. There can be multiple subscriptions in a Directory. 41 * **Core Domain**: The initial domain name `<tenant>.onmicrosoft.com` is the core domain. It is possible to define custom domain names too. 42 43 ## References 44 45 * [Az - Permissions for a Pentest - HackTricks](https://cloud.hacktricks.xyz/pentesting-cloud/azure-security/az-permissions-for-a-pentest) 46 * [An introduction to penetration testing Azure - HollyGraceful - 06 August 2021](https://akimbocore.com/article/introduction-to-pentesting-azure/) 47 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)