Skip to content
OPS // KITitspentest.sh

PE-AAD

AADInternals

PowerShell module exposing Azure AD/Entra ID and Office 365 internals — token acquisition, admin API access, and hybrid AD Connect analysis.

Official siteInstallBack to catalog

OVERVIEW

AADInternals (github.com/Gerenios/AADInternals) is a PowerShell module by Dr. Nestori Syynimaa (@DrAzureAD) that documents and exposes undocumented internal APIs and behaviors of Azure AD/Entra ID, Office 365, and Azure AD Connect. Its cmdlets cover authentication and token acquisition (`Get-AADIntAccessTokenForAADGraph`, `Get-AADIntAccessTokenForMSGraph`), tenant and user enumeration, and administrative actions not exposed through Microsoft's own tooling.

For post-exploitation work it is best known for two things: extracting and decrypting credentials cached by an on-premises Azure AD Connect server (`Get-AADIntSyncCredentials`), and its backdoor/persistence cmdlets (`Set-AADIntUserMFA`, `Open-AADIntUserPipe`, `ConvertTo-AADIntBackdoor`) that show how a compromised Global Administrator session can be turned into durable tenant access — a class of finding pentest teams use to demonstrate the real-world impact of Entra ID admin compromise.

USE CASES

Practical use cases

  • 01

    Acquiring Azure AD Graph and Microsoft Graph access tokens for a compromised identity to demonstrate downstream API access.

  • 02

    Extracting and decrypting Azure AD Connect sync account credentials from a compromised hybrid identity server.

  • 03

    Demonstrating backdoor persistence techniques (e.g. converting a user into a passwordless federated identity) to show the impact of Global Administrator compromise.

  • 04

    Enumerating tenant configuration, users, and domains through undocumented Azure AD/Office 365 admin APIs.

QUICK START

Once post-exploitation access to Azure AD/Entra ID or hybrid AD Connect is authorized, to acquire tokens, test backdoor persistence techniques, and inspect internal admin APIs.

  1. Install the module once the assessment scope explicitly covers Entra ID post-exploitation: `Install-Module AADInternals`.
  2. Import it and confirm which cmdlets are in scope for the engagement — AADInternals ships persistence and credential-extraction functions that go well beyond simple enumeration.
  3. Authenticate with the compromised or client-provisioned identity and cache a token, e.g. `Get-AADIntAccessTokenForAADGraph -SaveToCache`.
  4. Run only the specific enumeration or token-acquisition cmdlets agreed with the client; treat any backdoor/persistence cmdlet as a separate, explicitly authorized action.
Import-Module — bash
Import-Module AADInternals; Get-AADIntLoginInformation -UserName user@target.com

BEFORE YOU RUN IT

What to check before running it

Several cmdlets (backdoor creation, MFA bypass, AD Connect credential extraction) alter tenant state or persist access — these must be separately scoped and explicitly authorized in writing, distinct from read-only enumeration.

Token acquisition and Graph API calls made through AADInternals appear in Entra ID sign-in logs under the identity used; agree with the client on what activity to expect there for the blue-team debrief.

Never run AADInternals against a tenant or identity outside the signed scope — several cmdlets can modify authentication policy or federation settings and are difficult to cleanly revert.

KEEP EXPLORING

View the whole phase →