
A lightweight PowerShell tool for assessing the security posture of Microsoft Entra ID environments. It helps identify privileged objects, risky assignments, and potential misconfigurations.

EntraFalcon is a PowerShell-based assessment tool for pentesters, security analysts, and system administrators to evaluate the security posture of a Microsoft Entra ID environment.
Designed for ease of use, EntraFalcon runs on PowerShell 5.1 and 7, supports both Windows and Linux, and requires no additional PowerShell modules, extra installations, or Microsoft Graph API consent.
The tool helps uncover privileged objects, potentially risky assignments and Conditional Access misconfigurations that are often overlooked, such as:
Findings are presented in interactive HTML reports to support efficient exploration and analysis.
| Type | Permission | Mandatory | Impact if missing |
|---|---|---|---|
| Entra ID Role | Global Reader | Yes | Not possible to run the scripts |
| Azure Role | Reader: On every Management Group or Subscription | No | Can't assess Azure IAM assignments |
Furthermore, you must be able to authenticate to the Microsoft Graph API and optionally the Azure ARM API from the device where you run the tool. Ensure that Conditional Access Policies do not block your authentication.
To get started, clone the repository and navigate into the project directory:
git clone https://github.com/CompassSecurity/EntraFalcon
cd EntraFalcon
Note: You may need to temporarily change the PowerShell execution policy to run the script. Only do this for trusted scripts!
Set-ExecutionPolicy -ExecutionPolicy Unrestricted -Scope Process
EntraFalcon includes built-in support for Entra ID authentication. Use -AuthFlow to select the authentication flow.
For normal assessments, use one of the full-coverage flows:
| Recommended Flow | Best For | Platform | Coverage |
|---|---|---|---|
BroCi (default) | Interactive Windows runs | Windows | Full |
BroCiManualCode | Authentication in another browser | Windows, Linux, macOS | Full |
BroCiToken | Existing Azure Portal refresh token | Windows, Linux, macOS | Full |
ServicePrincipal | Automation / CI | Windows, Linux, macOS | Full |
BroCi uses one interactive login. BroCiToken and ServicePrincipal use none. Fallback user flows may require multiple interactive logins because separate resource tokens are requested.
Due to the lack of pre-consented first-party applications, the fallback flows cannot perform the full enumeration (PIM for Groups, Access Packages, Catalogs). Therefore, they currently remain fallback options only.
| Flow | Use Only When | Platform | Limitations |
|---|---|---|---|
AuthCode | Legacy compatibility is required | Windows | Partial coverage. No standalone PIM for Groups, Access Packages, or Catalogs report. |
DeviceCode | Browser-based authentication is not possible | Windows, Linux, macOS | Partial coverage. No standalone PIM for Groups, Access Packages, or Catalogs report. Some Security Findings checks run with reduced depth. |
ManualCode | Authentication must be completed through a separate browser session | Windows, Linux, macOS | Partial coverage. No standalone PIM for Groups, Access Packages, or Catalogs report. |
BroCi uses alternate first-party applications and requires only one interactive sign-in.
It is useful when the Azure Active Directory PowerShell client requires assignment and must be avoided.
.\run_EntraFalcon.ps1
Explicit BroCi selection:
.\run_EntraFalcon.ps1 -AuthFlow BroCi
.\run_EntraFalcon.ps1 -AuthFlow BroCiManualCode
Preserve log.code=1. and copy the request URL containing the code to the clipboard.If a valid Azure Portal refresh token is already available (client c44b4083-3bb0-49c1-b47d-974e53cbdf3c), it can be used directly. Example: Obtaining the refresh token from the browser
brk_client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c and extract the refresh token from the response..\run_EntraFalcon.ps1 -AuthFlow BroCiToken -BroCiToken "1.XXXXXXXXXXX"
Authenticates as a registered application using the OAuth2 client credentials grant — no user interaction required.
Useful for repeated automated executions.
Requires a custom Entra app registration with Application-type Graph API permissions (see below).
With client secret:
.\run_EntraFalcon.ps1 -AuthFlow ServicePrincipal -Tenant "mysecuretenant.ch" -SPClientId "<AppId>" -SPClientSecret "<Secret>"
With PFX certificate:
.\run_EntraFalcon.ps1 -AuthFlow ServicePrincipal -Tenant "mysecuretenant.ch" -SPClientId "<AppId>" -SPCertificatePath "C:\certs\app.pfx"
For a password-protected PFX, add -SPCertificatePassword (Read-Host -Prompt "Certificate password" -AsSecureString).