LogoClawIndex
CasesSkillsAbout
LogoClawIndex

auditing-entra-id-with-aadinternals - Auditing Entra ID with AADInternals

Drive AADInternals PowerShell toolkit for Microsoft Entra ID tenant reconnaissance, API token acquisition, and federation backdoor testing.

Tags

Updated: 2026-09-23

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Perform unauthenticated tenant reconnaissance
  • Enumerate verified domains and tenant ID
  • Enumerate external usernames
  • Acquire API access tokens
  • Enumerate authenticated directory objects
  • Inspect AD FS federation configuration
  • Export AD FS signing certificate
  • Test federation backdoor setup
  • Forge SAML tokens

Inputs

  • Target domain name
  • Candidate user principal names
  • Microsoft Entra ID credentials
  • Global Administrator credentials
  • AD FS server access
  • Target user ImmutableID

Outputs

  • Reconnaissance summary tables
  • User existence status
  • Cached API access tokens
  • Exported AD FS signing certificate file
  • Federation backdoor configuration
  • Forged SAML tokens
  • Authenticated Office 365 portal session

Requirements

  • Written testing authorization
  • Windows host with PowerShell 5.1 or higher
  • AADInternals PowerShell module
  • Global Administrator role for backdoor testing

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
aadinternals
entra-id
azure-ad
saml-token-forgery
federation-backdoor
token-manipulation
adfs
red-team
Perform unauthenticated tenant reconnaissance
Enumerate verified domains and tenant ID
Enumerate external usernames
Acquire API access tokens
Target domain name
Candidate user principal names
Microsoft Entra ID credentials
Reconnaissance summary tables
User existence status
Cached API access tokens