PE-AAD
AADInternals
PowerShell module exposing Azure AD/Entra ID and Office 365 internals — token acquisition, admin API access, and hybrid AD Connect analysis.
Official siteInstallBack to catalog
OVERVIEW
AADInternals (github.com/Gerenios/AADInternals) is a PowerShell module by Dr. Nestori Syynimaa (@DrAzureAD) that documents and exposes undocumented internal APIs and behaviors of Azure AD/Entra ID, Office 365, and Azure AD Connect. Its cmdlets cover authentication and token acquisition (`Get-AADIntAccessTokenForAADGraph`, `Get-AADIntAccessTokenForMSGraph`), tenant and user enumeration, and administrative actions not exposed through Microsoft's own tooling.
For post-exploitation work it is best known for two things: extracting and decrypting credentials cached by an on-premises Azure AD Connect server (`Get-AADIntSyncCredentials`), and its backdoor/persistence cmdlets (`Set-AADIntUserMFA`, `Open-AADIntUserPipe`, `ConvertTo-AADIntBackdoor`) that show how a compromised Global Administrator session can be turned into durable tenant access — a class of finding pentest teams use to demonstrate the real-world impact of Entra ID admin compromise.
USE CASES
Practical use cases
- 01
Acquiring Azure AD Graph and Microsoft Graph access tokens for a compromised identity to demonstrate downstream API access.
- 02
Extracting and decrypting Azure AD Connect sync account credentials from a compromised hybrid identity server.
- 03
Demonstrating backdoor persistence techniques (e.g. converting a user into a passwordless federated identity) to show the impact of Global Administrator compromise.
- 04
Enumerating tenant configuration, users, and domains through undocumented Azure AD/Office 365 admin APIs.
QUICK START
Once post-exploitation access to Azure AD/Entra ID or hybrid AD Connect is authorized, to acquire tokens, test backdoor persistence techniques, and inspect internal admin APIs.
- Install the module once the assessment scope explicitly covers Entra ID post-exploitation: `Install-Module AADInternals`.
- Import it and confirm which cmdlets are in scope for the engagement — AADInternals ships persistence and credential-extraction functions that go well beyond simple enumeration.
- Authenticate with the compromised or client-provisioned identity and cache a token, e.g. `Get-AADIntAccessTokenForAADGraph -SaveToCache`.
- Run only the specific enumeration or token-acquisition cmdlets agreed with the client; treat any backdoor/persistence cmdlet as a separate, explicitly authorized action.
Import-Module AADInternals; Get-AADIntLoginInformation -UserName user@target.comBEFORE YOU RUN IT
What to check before running it
Several cmdlets (backdoor creation, MFA bypass, AD Connect credential extraction) alter tenant state or persist access — these must be separately scoped and explicitly authorized in writing, distinct from read-only enumeration.
Token acquisition and Graph API calls made through AADInternals appear in Entra ID sign-in logs under the identity used; agree with the client on what activity to expect there for the blue-team debrief.
Never run AADInternals against a tenant or identity outside the signed scope — several cmdlets can modify authentication policy or federation settings and are difficult to cleanly revert.