attacking-entra-id

Installation
SKILL.md

Attacking Entra ID

Entra ID (formerly Azure AD) is the identity control plane for Microsoft 365, Azure, and thousands of SaaS integrations. Compromising it grants access to everything those identities protect: mailboxes, SharePoint, Azure subscriptions, and any application that trusts the tenant. Despite this, Entra ID environments are routinely less monitored than on-premises Active Directory. Most organizations lack equivalent detection coverage for cloud identity attacks, and the attack surface -- OAuth tokens, application consent, service principals, Conditional Access gaps -- is fundamentally different from traditional AD.

Only against tenants you are authorized to test.

When to Use

Installs
21
GitHub Stars
146
First Seen
Jul 30, 2026
attacking-entra-id — trilwu/secskills