Skip to content
OPS // KITitspentest.sh

PE-SEA

SeamlessPass

Converts on-premises Kerberos tickets into Microsoft 365 / Entra ID access tokens by abusing Azure AD Seamless SSO (Desktop SSO).

Official siteBack to catalog

OVERVIEW

SeamlessPass (github.com/Malcrove/SeamlessPass) is a red-team tool that weaponizes Azure AD Seamless Single Sign-On (also called Desktop SSO) — the hybrid-identity feature that lets domain-joined machines sign into Entra ID without a password prompt, by exchanging a Kerberos service ticket for the `AZUREADSSOACC$` computer account for a cloud access token.

Given the ingredients an attacker typically already has after compromising on-premises AD — a stolen TGT, a user's NTLM hash or AES key, a forged Golden Ticket, or the `AZUREADSSOACC$` account's own secret — SeamlessPass requests or forges the Kerberos service ticket for that account, then exchanges it directly with Entra ID for a working Microsoft 365 access token, without ever touching the domain controller's network segment if the on-prem secret is already known.

USE CASES

Practical use cases

  • 01

    Demonstrating cloud impact from an on-prem AD compromise where Seamless SSO is enabled, as part of a red team engagement.

  • 02

    Converting a captured TGT or a user's NTLM/AES key into a live Microsoft 365 session for follow-on API access (Graph, ROADTools, AADInternals).

  • 03

    Testing whether a compromised `AZUREADSSOACC$` secret alone is enough to impersonate arbitrary users in Entra ID.

  • 04

    Validating detections around anomalous Seamless SSO sign-ins during a purple-team exercise.

QUICK START

In post-exploitation, once on-premises Active Directory is compromised, to demonstrate how that compromise pivots into Microsoft 365 / Entra ID via Seamless SSO.

  1. Clone the repository and install its Python dependencies with `pip install -r requirements.txt`.
  2. Confirm the target tenant actually has Seamless SSO enabled and identify the tenant's domain and Entra ID tenant name.
  3. Gather one supported credential: a stolen TGT, a user's NTLM hash/AES key plus SID, or the `AZUREADSSOACC$` account's NTLM hash/AES key.
  4. Run SeamlessPass with the matching authentication flags and the domain controller reachable if a live ticket exchange is needed.
  5. Use the returned Microsoft 365 access token with Graph API calls, ROADTools, or AADInternals to demonstrate cloud impact.
seamlesspass — bash
seamlesspass -tenant corp.com -domain corp.local -dc dc.corp.local -tgt <base64_TGT>

BEFORE YOU RUN IT

What to check before running it

This tool operates on already-compromised on-prem AD material (TGTs, NTLM hashes, AES keys) — it is a post-exploitation pivot, not an initial-access technique, and must stay inside an authorized engagement's AD and Entra ID scope.

Forged or replayed Kerberos tickets and the resulting Entra ID sign-ins can surface in Entra ID sign-in logs and Microsoft Defender for Identity/Entra ID Protection — coordinate timing and expected activity with the client's blue team beforehand.

Access to the `AZUREADSSOACC$` account's secret is highly sensitive; handle and dispose of any extracted credential material per the engagement's rules of engagement.

KEEP EXPLORING

View the whole phase →