Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
AzureADEnumeration — Microsoft Entra ID (Azure AD) Unauthenticated Enumeration | Kitploit
Tools/GitHubGitHub/logisek/azureadenumeration
Cloud Infrastructure SecurityOSINT (Open Source Intelligence)ReconnaissanceInformation GatheringPenetration TestingCloud SecuritySubdomain EnumerationEmail SecurityDNS Analysis
GitHublogisek/azureadenumeration

AzureADEnumeration

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

795287 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

Microsoft Entra ID (Azure AD) Unauthenticated Enumeration

Source: EvilMist Toolkit - Invoke-EntraEnum.ps1 - https://github.com/Logisek/EvilMist


1. Tenant Discovery (-TenantInfo)

Discovers tenant information using public APIs.

1.1 azmap.dev API

Retrieves tenant details from the azmap.dev service.

# Replace DOMAIN with target domain (e.g., example.com)
curl -s "https://azmap.dev/api/tenant?domain=DOMAIN&extract=true"

Response contains: tenantId, displayName, countryCode

1.2 OpenID Configuration

Retrieves OpenID Connect configuration including token endpoints.

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/v2.0/.well-known/openid-configuration"

Response contains: token_endpoint, authorization_endpoint, jwks_uri, issuer


2. Domain Realm Information (-DomainRealm)

Retrieves domain namespace and federation configuration.

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=enum@DOMAIN&json=1"

Response contains:

  • NameSpaceType - "Managed" or "Federated"
  • AuthURL - Federation authentication URL (if federated)
  • CloudInstanceName - Cloud instance (e.g., "microsoftonline.com")
  • FederationBrandName - Organization branding name
  • DomainName - Verified domain

3. User Enumeration via GetCredentialType (-UserEnum)

Checks if a user exists in Azure AD. Returns different codes based on user existence.

# Replace EMAIL with target email address
curl -s -X POST "https://login.microsoftonline.com/common/GetCredentialType" \
  -H "Content-Type: application/json" \
  -d '{
    "Username": "EMAIL",
    "isOtherIdpSupported": true,
    "checkPhones": false,
    "isRemoteNGCSupported": true,
    "isCookieBannerShown": false,
    "isFidoSupported": true,
    "originalRequest": "",
    "country": "US",
    "forceotclogin": false,
    "isExternalFederationDisallowed": false,
    "isRemoteConnectSupported": false,
    "federationFlags": 0,
    "isSignup": false,
    "flowToken": "",
    "isAccessPassSupported": true
  }'

IfExistsResult codes:

  • 0 = User exists (Azure IdP)
  • 1 = User does not exist
  • 2 = Invalid request
  • 4 = Server error
  • 5 = User exists (Federated IdP)
  • 6 = User exists (External non-MS IdP)

4. DNS Reconnaissance (-DnsEnum)

DNS queries for Azure/M365 related records. Use dig, nslookup, or host commands.

4.1 CNAME Records

# Main domain CNAME
dig CNAME DOMAIN

# Autodiscover CNAME
dig CNAME autodiscover.DOMAIN
dig CNAME lyncdiscover.DOMAIN
dig CNAME sip.DOMAIN

4.2 TXT/SPF Records

dig TXT DOMAIN

4.3 SRV Records

dig SRV _ldap._tcp.DOMAIN
dig SRV _kerberos._tcp.DOMAIN
dig SRV _autodiscover._tcp.DOMAIN
dig SRV _sip._tls.DOMAIN
dig SRV _sipfederationtls._tcp.DOMAIN

4.4 MX Records

dig MX DOMAIN

5. OneDrive User Enumeration (-OneDriveEnum)

Completely undetectable - No audit logs generated.

Checks if a user exists by probing their OneDrive personal site URL.

# Replace TENANT with tenant name (e.g., example)
# Replace USERPATH with email formatted as: user_domain_com (@ and . replaced with _)
# Example: [email protected] becomes john_doe_example_com

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://TENANT-my.sharepoint.com/personal/USERPATH/_layouts/15/onedrive.aspx"

Status codes:

  • 200 = User exists, OneDrive accessible
  • 401/403 = User exists, access denied
  • 404 = User does not exist

Example for user [email protected]:

curl -s -o /dev/null -w "%{http_code}" -I \
  "https://example-my.sharepoint.com/personal/john_doe_example_com/_layouts/15/onedrive.aspx"

6. Federation Metadata (-FederationMeta)

Retrieves federation metadata including signing certificates and token endpoints.

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/DOMAIN/FederationMetadata/2007-06/FederationMetadata.xml"

Response contains (XML):

  • Entity ID
  • X509 Signing Certificates
  • Token Endpoints
  • NameID Formats
  • Claim Types
  • ADFS server information (if federated)

7. Seamless SSO Detection (-SeamlessSSO)

Detects if Desktop SSO (Seamless Single Sign-On) is enabled.

7.1 Check SSO Configuration

# Replace DOMAIN with target domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=user@DOMAIN&json=1"

Look for: DesktopSsoEnabled: true

7.2 Test Autologon Endpoint (if SSO enabled)

# Replace TENANT_ID with the tenant GUID
curl -s -o /dev/null -w "%{http_code}" \
  "https://autologon.microsoftazuread-sso.com/TENANT_ID/winauth/trust/2005/usernamemixed"

8. Azure Subdomain Enumeration (-SubdomainEnum)

Discovers Azure resources associated with a tenant. Uses DNS resolution.

Core Azure Subdomains to Check:

# Replace TENANT with tenant name

# Primary tenant domain
dig A TENANT.onmicrosoft.com

# SharePoint
dig A TENANT.sharepoint.com

# OneDrive
dig A TENANT-my.sharepoint.com

# Azure Blob Storage
dig A TENANT.blob.core.windows.net

# Azure Files
dig A TENANT.file.core.windows.net

# Azure Queue
dig A TENANT.queue.core.windows.net

# Azure Table
dig A TENANT.table.core.windows.net

# Key Vault
dig A TENANT.vault.azure.net

# Azure SQL
dig A TENANT.database.windows.net

# App Service
dig A TENANT.azurewebsites.net

# Kudu/Git Deployment
dig A TENANT.scm.azurewebsites.net

# Cloud Services
dig A TENANT.cloudapp.net
dig A TENANT.cloudapp.azure.com

# Exchange Online Protection
dig A TENANT.mail.protection.outlook.com

# Container Registry
dig A TENANT.azurecr.io

# Redis Cache
dig A TENANT.redis.cache.windows.net

# Service Bus
dig A TENANT.servicebus.windows.net

# Front Door
dig A TENANT.azurefd.net

# Azure AD B2C
dig A TENANT.b2clogin.com

# API Management
dig A TENANT.azure-api.net

# Traffic Manager
dig A TENANT.trafficmanager.net

# HDInsight
dig A TENANT.azurehdinsight.net

# Cosmos DB
dig A TENANT.documents.azure.com

# Cognitive Search
dig A TENANT.search.windows.net

# Cognitive Services
dig A TENANT.cognitiveservices.azure.com

Permutation Examples:

# Common suffixes: dev, prod, staging, test, uat, qa, backup, dr, api, app, web, data
dig A TENANTdev.blob.core.windows.net
dig A TENANTprod.azurewebsites.net
dig A TENANTstaging.vault.azure.net

9. Autodiscover V2 Enumeration (-AutodiscoverEnum)

Checks user existence via Autodiscover V2 JSON endpoint.

# Replace EMAIL with target email address
curl -s -o /dev/null -w "%{http_code}" -L --max-redirs 0 \
  "https://autodiscover-s.outlook.com/autodiscover/autodiscover.json?Email=EMAIL&Protocol=Autodiscoverv1"

Status codes:

  • 200 = User exists
  • 302 (redirect) = User does not exist
  • 401/403 = User exists (auth required)

10. Autodiscover V1 Enumeration (-AutodiscoverV1Enum)

Legacy XML-based Autodiscover endpoint for user enumeration.

# Replace DOMAIN with target domain
# Replace EMAIL with target email address

curl -s -X POST "https://autodiscover.DOMAIN/autodiscover/autodiscover.xml" \
  -H "Content-Type: text/xml; charset=utf-8" \
  -d '<?xml version="1.0" encoding="utf-8"?>
<Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/requestschema/2006">
  <Request>
    <EMailAddress>EMAIL</EMailAddress>
    <AcceptableResponseSchema>http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a</AcceptableResponseSchema>
  </Request>
</Autodiscover>'

Response indicators:

  • RedirectAddr in response = User exists
  • RedirectUrl in response = May indicate existence
  • ErrorCode: InvalidUser = User does not exist
  • ErrorCode: NoError = User exists

11. Exchange Web Services (EWS) Probe (-EwsProbe)

Probes EWS endpoints for exposure.

Download Tool