A production-ready tool for detecting authentication misconfigurations in Azure environments. This tool tests various client IDs against Microsoft Graph, Azure Resource Manager, and Exchange Online to identify potential security vulnerabilities.
- User-friendly prompts for all configuration options
- Resource selection (Graph, ARM, EWS)
- Client ID selection from multiple sources
- Credential input with secure password handling
- NEW: Choose to execute immediately or generate command line
- NEW: Auto-generate executable shell scripts
- NEW: Save configuration as JSON for reuse
- Full CLI support with all options
- Configuration file support for automated runs
- Batch processing capabilities
- Timestamped output files for each scan
- Comprehensive summary reports with security alerts
- Retry logic with exponential backoff
- Detailed logging support
- Thread-safe result writing
- Detects successful authentications (potential misconfigurations)
- Detailed analysis of client ID permissions
- User and scope information extraction
- HTTP endpoint probing for validation
pip install -r requirements.txtpython3 azure_test.py --interactiveThe interactive mode now offers two execution options:
- Execute now: Run the scan immediately with your settings
- Generate command: Create a one-liner command and executable script for later use
When you choose "Generate command", the tool will:
- Create an executable shell script with your exact settings
- Optionally save the configuration as a JSON file for reuse
- Display the command line for easy copying
# Basic ROPC scan
python3 azure_test.py --mode ropc --tenant <TENANT_ID> --username user@domain.com --password 'password'
# Device code flow
python3 azure_test.py --mode device --tenant <TENANT_ID> --client-list clients.txt
# With specific targets
python3 azure_test.py --mode ropc --tenant <TENANT_ID> --username user@domain.com --password 'password' --targets graph,arm
# Using configuration file
python3 azure_test.py --config my_config.jsonCreate a configuration file for automated runs:
# Generate template
python3 azure_test.py --save-config my_config.json
# Use configuration
python3 azure_test.py --config my_config.jsonExample configuration:
{
"mode": "ropc",
"tenant": "your-tenant-id",
"username": "user@domain.com",
"password": "your-password",
"targets": ["graph", "arm", "ews"],
"client_list": "clients.txt",
"max_threads": 6,
"delay": 0.5,
"verbose": false
}Each scan generates timestamped files:
azure_auth_scan_YYYYMMDD_HHMMSS.csv- Detailed results in CSV formatazure_auth_scan_YYYYMMDD_HHMMSS.jsonl- Results in JSON Lines formatscan_summary_YYYYMMDD_HHMMSS.txt- Human-readable summary report
When using "Generate command" mode, additional files are created:
generated_command_YYYYMMDD_HHMMSS.sh- Executable shell script with your settingsconfig_YYYYMMDD_HHMMSS.json- Configuration file (optional, if you choose to save)temp_clients_YYYYMMDD_HHMMSS.txt- Temporary client ID list (if using custom client list)
The tool automatically detects and reports:
- ✅ Successful authentications (potential misconfigurations)
- 🚨 Client IDs with excessive permissions
- 📊 Detailed breakdown by resource and user
⚠️ Common failure patterns
For 24/7 monitoring, set up a cron job:
# Run daily at 2 AM
0 2 * * * /path/to/python3 /path/to/azure_test.py --config /path/to/production_config.json--mode {ropc,device} Authentication mode
--tenant TENANT Azure tenant ID
--client-id CLIENT_ID Single client ID to test
--client-list FILE File with client IDs (one per line)
--client-list-url URL Remote URL with client IDs
--username USERNAME Username for ROPC mode
--password PASSWORD Password for ROPC mode
--targets TARGETS Comma-separated targets (graph,arm,ews)
--max-threads N Number of concurrent workers (default: 6)
--delay SECONDS Delay between requests (default: 0.5)
--limit N Limit number of client IDs (0 = all)
--interactive Run in interactive mode
--verbose, -v Enable verbose logging
--config FILE Load configuration from JSON file
--save-config FILE Save configuration template
- ROPC mode may trigger account lockouts or security alerts
- Device code mode requires manual user interaction
- Monitor for unusual authentication patterns
- Consider running during off-peak hours
- Review and validate all successful authentications
- Import errors: Install dependencies with
pip install -r requirements.txt - Authentication failures: Verify tenant ID and credentials
- Network timeouts: Increase delay between requests with
--delay - Permission errors: Ensure write access to output directory
Enable verbose logging for troubleshooting:
python3 azure_test.py --verbose --interactiveThis tool is for security testing and educational purposes only. Use responsibly and in accordance with your organization's security policies.