auditing-entra-id-with-aadinternals - Audit Microsoft Entra ID and AD FS using AADInternals.
Perform Microsoft Entra ID tenant reconnaissance, access-token acquisition, and federation backdoor testing using the AADInternals PowerShell toolkit.
Tags
Updated: 2026-09-23Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Perform unauthenticated tenant reconnaissance
- Enumerate candidate user accounts
- Acquire Microsoft API access tokens
- Enumerate directory users and privileges
- Inspect AD FS signing certificates
- Test federation backdoor configurations
- Forge SAML authentication tokens
Inputs
- Target domain name
- Candidate UPN list
- User credentials
- Global Administrator account credentials
- Target user ImmutableID
- AD FS server access
Outputs
- Tenant reconnaissance details
- Cached Microsoft API access tokens
- Directory enumeration results
- Exported AD FS signing certificate PFX file
- Forged SAML authentication token
Requirements
- Written authorization for identity attack testing
- Windows host with PowerShell 5.1+ or PowerShell 7
- AADInternals PowerShell module
- Global Administrator privileges for backdoor testing
