Skip to content

Repository files navigation

Azure Auth Security Scanner

A production-ready tool for detecting authentication misconfigurations in Azure environments. This tool tests various client IDs against Microsoft Graph, Azure Resource Manager, and Exchange Online to identify potential security vulnerabilities.

Features

🔧 Interactive Mode

  • User-friendly prompts for all configuration options
  • Resource selection (Graph, ARM, EWS)
  • Client ID selection from multiple sources
  • Credential input with secure password handling
  • NEW: Choose to execute immediately or generate command line
  • NEW: Auto-generate executable shell scripts
  • NEW: Save configuration as JSON for reuse

🚀 Command Line Mode

  • Full CLI support with all options
  • Configuration file support for automated runs
  • Batch processing capabilities

📊 Production Ready

  • Timestamped output files for each scan
  • Comprehensive summary reports with security alerts
  • Retry logic with exponential backoff
  • Detailed logging support
  • Thread-safe result writing

🔍 Security Focus

  • Detects successful authentications (potential misconfigurations)
  • Detailed analysis of client ID permissions
  • User and scope information extraction
  • HTTP endpoint probing for validation

Installation

pip install -r requirements.txt

Usage

Interactive Mode (Recommended for first-time use)

python3 azure_test.py --interactive

The interactive mode now offers two execution options:

  • Execute now: Run the scan immediately with your settings
  • Generate command: Create a one-liner command and executable script for later use

When you choose "Generate command", the tool will:

  • Create an executable shell script with your exact settings
  • Optionally save the configuration as a JSON file for reuse
  • Display the command line for easy copying

Command Line Mode

# Basic ROPC scan
python3 azure_test.py --mode ropc --tenant <TENANT_ID> --username user@domain.com --password 'password'

# Device code flow
python3 azure_test.py --mode device --tenant <TENANT_ID> --client-list clients.txt

# With specific targets
python3 azure_test.py --mode ropc --tenant <TENANT_ID> --username user@domain.com --password 'password' --targets graph,arm

# Using configuration file
python3 azure_test.py --config my_config.json

Configuration File

Create a configuration file for automated runs:

# Generate template
python3 azure_test.py --save-config my_config.json

# Use configuration
python3 azure_test.py --config my_config.json

Example configuration:

{
  "mode": "ropc",
  "tenant": "your-tenant-id",
  "username": "user@domain.com",
  "password": "your-password",
  "targets": ["graph", "arm", "ews"],
  "client_list": "clients.txt",
  "max_threads": 6,
  "delay": 0.5,
  "verbose": false
}

Output Files

Each scan generates timestamped files:

  • azure_auth_scan_YYYYMMDD_HHMMSS.csv - Detailed results in CSV format
  • azure_auth_scan_YYYYMMDD_HHMMSS.jsonl - Results in JSON Lines format
  • scan_summary_YYYYMMDD_HHMMSS.txt - Human-readable summary report

When using "Generate command" mode, additional files are created:

  • generated_command_YYYYMMDD_HHMMSS.sh - Executable shell script with your settings
  • config_YYYYMMDD_HHMMSS.json - Configuration file (optional, if you choose to save)
  • temp_clients_YYYYMMDD_HHMMSS.txt - Temporary client ID list (if using custom client list)

Security Alerts

The tool automatically detects and reports:

  • ✅ Successful authentications (potential misconfigurations)
  • 🚨 Client IDs with excessive permissions
  • 📊 Detailed breakdown by resource and user
  • ⚠️ Common failure patterns

Production Deployment

For 24/7 monitoring, set up a cron job:

# Run daily at 2 AM
0 2 * * * /path/to/python3 /path/to/azure_test.py --config /path/to/production_config.json

Command Line Options

--mode {ropc,device}     Authentication mode
--tenant TENANT          Azure tenant ID
--client-id CLIENT_ID    Single client ID to test
--client-list FILE       File with client IDs (one per line)
--client-list-url URL    Remote URL with client IDs
--username USERNAME      Username for ROPC mode
--password PASSWORD      Password for ROPC mode
--targets TARGETS        Comma-separated targets (graph,arm,ews)
--max-threads N          Number of concurrent workers (default: 6)
--delay SECONDS          Delay between requests (default: 0.5)
--limit N                Limit number of client IDs (0 = all)
--interactive            Run in interactive mode
--verbose, -v            Enable verbose logging
--config FILE            Load configuration from JSON file
--save-config FILE       Save configuration template

Security Considerations

⚠️ Important: This tool tests authentication against live Azure services. Use responsibly:

  • ROPC mode may trigger account lockouts or security alerts
  • Device code mode requires manual user interaction
  • Monitor for unusual authentication patterns
  • Consider running during off-peak hours
  • Review and validate all successful authentications

Troubleshooting

Common Issues

  1. Import errors: Install dependencies with pip install -r requirements.txt
  2. Authentication failures: Verify tenant ID and credentials
  3. Network timeouts: Increase delay between requests with --delay
  4. Permission errors: Ensure write access to output directory

Debug Mode

Enable verbose logging for troubleshooting:

python3 azure_test.py --verbose --interactive

License

This tool is for security testing and educational purposes only. Use responsibly and in accordance with your organization's security policies.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages