Azure Enumeration
Unauthenticated
Microsoft endpoints reveal whether a user accounts exists. For instance, during a login attempt the API response may have a flag IfExistResult.
Many Azure resources are discoverable via predictable domain patterns. Tools like Microburst can automate subdomain brute-forcing.
Public-facing Azures services may allow enumeration or direct exploitation. As well as OSINT can collect leaked credentials.
Authenticated
Given credentials or tokens, attacker can perform deep enumeration. Some tools include:
- RoadRecon gathers information about users, apps, and roles.
- AzureHound is the extension of Bloodhound for Azure, mapping attack paths.
- Microburst supports unauthenticated and authnenticated recon.
- Stormspotter gives passive/active cloud reconnaissance.
- Monkey 365 is a Microsoft 365 enumerator.
We might encounter custom APIs or non-standard object types that might require some form of custom tooling. It’s important to note that each API gives different uses
- Graph is the primary API for identity data.
- Azure Resource Manager is for resource data
- Service-specific endpoints require tokens issue for their resources.
We often need specific authentication options for tooling, therefore, we need to request the right access token. OAuth v2 (scope-based) requests return an Access Token for Graph, while OAuth v1 (Resource) requests return a token for ARM.
# OAuth v2 (scope-based) access token request
# returns an Access Token for Graph
POST https://login.microsoftonline.com/<TENANT>/oauth2/v2.0/token
Content-Type: application/x-www-form-urlencoded
client_id=<CLIENT_ID>&
client_secret=<CLIENT_SECRET>&
grant_type=client_credentials&
scope=https://graph.microsoft.com/.default
# OAuth v1 (Resource)
# returns a token for ARM
POST https://login.microsoftonline.com/<TENANT>/oauth2/token
Content-Type: application/x-www-form-urlencoded
grant_type=client_credentials&
client_id=<CLIENT_ID>&
client_secret=<CLIENT_SECRET>&
resource=https://management.azure.com/
# graph token
az login
az account get-access-token --resource https://graph.microsoft.com
# ARM token
az account get-access-token --resource https://management.azure.com
# call Graph REST Api with token
Invoke-RestMethod -Uri https://graph.microsoft.com/v1.0/users -Headers @{ Authorization = Bearer $token }Enumerating Resources
A typical approach to enumeration would be
- Start with identity: enumerate apps, service principals, etc.
- Map Role Assignments: Use ARM to list roleAssignments scoped at subscription/resource
- Enumerate Resources: List resource types and probe public endpoints discovered from asset enumeration
- Correlate: Identity —> Role —> resource to find attack paths
- Pivot to data plane: Request data-plane tokens to get to key vault / storage
# enumerate Azure resources
az resource list -o table
Get-AzResourceSecurity Controls
Conditional Access Policies (CAP) is a control engine that evaluates sign-in and session context (location, device, …) and enforces actions such as MFA, block, or require device. It has risk-based policies, MFA enforcement, device compliance checks, location-based control, conditional access app control, etc.
Azure policy is a governance engine that enforces rules and effects on Azure resources ensuring resources comply with standards.
TLDR; CAP is the access-time decision and Azure Policy is the resource configuration guardrail.