daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-services-microsoft-intune.md (4168B)


      1 ---
      2 title: "Azure Services - Microsoft Intune"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-services-microsoft-intune.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-microsoft-intune.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure Services - Microsoft Intune
     12 
     13 Microsoft Intune is a cloud-based service that provides mobile device management (MDM) and mobile application management (MAM). It allows organizations to control and secure access to corporate data on mobile devices, including smartphones, tablets, and PCs. With Intune, businesses can enforce security policies, manage apps, and ensure that devices comply with organizational requirements, whether they are company-owned or personal (BYOD).
     14 
     15 ## Intunes Administration
     16 
     17 **Requirements**:
     18 
     19 * **Global Administrator** or **Intune Administrator** Privilege
     20 
     21     ```powershell
     22     Get-AzureADGroup -Filter "DisplayName eq 'Intune Administrators'"
     23     ```
     24 
     25 **Walkthrough**
     26 
     27 1. Login into <https://endpoint.microsoft.com/#home> or use Pass-The-PRT
     28 2. Go to **Devices** -> **All Devices** to check devices enrolled to Intune
     29 3. Go to **Scripts** and click on **Add** for Windows 10.
     30 4. Add a **Powershell script**
     31 5. Specify **Add all users** and **Add all devices** in the **Assignments** page.
     32 
     33 :warning: It will take up to one hour before you script is executed !
     34 
     35 ## Intune Scripts
     36 
     37 **Requirements**:
     38 
     39 * App with permission: `DeviceManagementConfiguration.Read.All`
     40 * `Microsoft.Graph.Intune` dependency installed: `Install-Module Microsoft.Graph.Intune`
     41 
     42 **Extract Intune scripts**:
     43 
     44 The following scripts are deprecated, use `MgGraph` instead of `MsGraph`, and change the appropriate function `InvokeMgGraph` too.
     45 
     46 * [okieselbach/Get-DeviceManagementScripts.ps1](https://raw.githubusercontent.com/okieselbach/Intune/master/Get-DeviceManagementScripts.ps1) - Get all or individual Intune PowerShell scripts and save them in specified folder.
     47 
     48     ```ps1
     49     Get-DeviceManagementScripts -FolderPath C:\temp -FileName myScript.ps1
     50     ```
     51 
     52 * [okieselbach/Get-DeviceHealthScripts.ps1](https://raw.githubusercontent.com/okieselbach/Intune/master/Get-DeviceHealthScripts.ps1) - Get all or individual Intune PowerShell Health scripts (aka Proactive Remediation scripts) and save them in specified folder.
     53 
     54     ```ps1
     55     Get-DeviceHealthScripts -FolderPath C:\temp\HealthScripts
     56     ```
     57 
     58 * [secureworks/pytune](https://github.com/secureworks/pytune) - Pytune is a post-exploitation tool for enrolling a fake device into Intune with mulitple platform support.
     59 
     60     ```ps1
     61     python3 pytune.py entra_join -o Windows -d Windows_pytune -u testuser@*******.onmicrosoft.com -p ***********  
     62     python3 pytune.py enroll_intune -o Windows -d Windows_pytune -c Windows_pytune.pfx -u testuser@*******.onmicrosoft.com -p *********** 
     63     python3 pytune.py download_apps -d Windows_pytune -m Windows_pytune_mdm.pfx
     64     ```
     65 
     66 ## LAPS
     67 
     68 Some organization have recreated LAPS for Azure devices using Intune scripts.
     69 
     70 ```ps1
     71 #requires -modules Microsoft.Graph.Authentication
     72 #requires -modules Microsoft.Graph.Intune
     73 #requires -modules LAPS
     74 #requires -modules ImportExcel
     75 
     76 $DaysBack = 30
     77 Connect-MgGraph
     78 Get-IntuneManagedDevice -Filter "Platform eq 'Windows'" |
     79     Foreach-Object {Get-LapsAADPassword -DevicesIds $_.DisplayName} |
     80         Where-Object {$_.PasswordExpirationTime -lt (Get-Date).AddDays(-$DaysBack)} |
     81             Export-Excel -Path "c:\temp\lapsdata.xlsx" - ClearSheet -AutoSize -Show
     82 ```
     83 
     84 ## References
     85 
     86 * [Microsoft Intune - Microsoft Intune support for Windows LAPS](https://learn.microsoft.com/en-us/mem/intune/protect/windows-laps-overview)
     87 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)
     88 * [Get back your Intune Proactive Remediation Scripts - Oliver Kieselbach - September 7, 2022](https://oliverkieselbach.com/2022/09/07/get-back-your-intune-proactive-remediation-scripts/)
     89 * [Get back your Intune PowerShell Scripts - Oliver Kieselbach - February 6, 2020](https://oliverkieselbach.com/2020/02/06/get-back-your-intune-powershell-scripts/)