PE-SEA
SeamlessPass
Converts on-premises Kerberos tickets into Microsoft 365 / Entra ID access tokens by abusing Azure AD Seamless SSO (Desktop SSO).
OVERVIEW
SeamlessPass (github.com/Malcrove/SeamlessPass) is a red-team tool that weaponizes Azure AD Seamless Single Sign-On (also called Desktop SSO) — the hybrid-identity feature that lets domain-joined machines sign into Entra ID without a password prompt, by exchanging a Kerberos service ticket for the `AZUREADSSOACC$` computer account for a cloud access token.
Given the ingredients an attacker typically already has after compromising on-premises AD — a stolen TGT, a user's NTLM hash or AES key, a forged Golden Ticket, or the `AZUREADSSOACC$` account's own secret — SeamlessPass requests or forges the Kerberos service ticket for that account, then exchanges it directly with Entra ID for a working Microsoft 365 access token, without ever touching the domain controller's network segment if the on-prem secret is already known.
USE CASES
Practical use cases
- 01
Demonstrating cloud impact from an on-prem AD compromise where Seamless SSO is enabled, as part of a red team engagement.
- 02
Converting a captured TGT or a user's NTLM/AES key into a live Microsoft 365 session for follow-on API access (Graph, ROADTools, AADInternals).
- 03
Testing whether a compromised `AZUREADSSOACC$` secret alone is enough to impersonate arbitrary users in Entra ID.
- 04
Validating detections around anomalous Seamless SSO sign-ins during a purple-team exercise.
QUICK START
In post-exploitation, once on-premises Active Directory is compromised, to demonstrate how that compromise pivots into Microsoft 365 / Entra ID via Seamless SSO.
- Clone the repository and install its Python dependencies with `pip install -r requirements.txt`.
- Confirm the target tenant actually has Seamless SSO enabled and identify the tenant's domain and Entra ID tenant name.
- Gather one supported credential: a stolen TGT, a user's NTLM hash/AES key plus SID, or the `AZUREADSSOACC$` account's NTLM hash/AES key.
- Run SeamlessPass with the matching authentication flags and the domain controller reachable if a live ticket exchange is needed.
- Use the returned Microsoft 365 access token with Graph API calls, ROADTools, or AADInternals to demonstrate cloud impact.
seamlesspass -tenant corp.com -domain corp.local -dc dc.corp.local -tgt <base64_TGT>BEFORE YOU RUN IT
What to check before running it
This tool operates on already-compromised on-prem AD material (TGTs, NTLM hashes, AES keys) — it is a post-exploitation pivot, not an initial-access technique, and must stay inside an authorized engagement's AD and Entra ID scope.
Forged or replayed Kerberos tickets and the resulting Entra ID sign-ins can surface in Entra ID sign-in logs and Microsoft Defender for Identity/Entra ID Protection — coordinate timing and expected activity with the client's blue team beforehand.
Access to the `AZUREADSSOACC$` account's secret is highly sensitive; handle and dispose of any extracted credential material per the engagement's rules of engagement.