National Cyber Warfare Foundation (NCWF)

Automating Azure AD outsider reconnaissance with AADOutsider-py


0 user ratings
2026-09-22 09:33:20
milo
Red Team (CNA)
"Automating

AADOutsider-py is a Python3 reimplementation of the AADInternals recon-as-outsider kill chain, letting authorized assessors map Entra ID tenants and validate user existence from unauthenticated vantage points.








Toolsynacktiv/AADOutsider-py — Python3 rewrite of the Invoke-AADIntReconAsOutsider and Invoke-AADIntUserEnumerationAsOutsider functions from AADInternals
CategoryCloud identity reconnaissance / OSINT against Azure AD (Entra ID)
Primary UseMapping tenant metadata, domain records, and Managed vs Federated status, plus validating username existence via the recon and user_enum subcommands
Safe UseIntended for penetration testers and red teamers with written authorization against client tenants, and for blue teams auditing what unauthenticated observers can learn about their own identity infrastructure
Telemetry NoteQueries Microsoft public endpoints (GetCredentialType-style login flows, autologon, rst2) and DNS; defenders can detect bursts of username-validation attempts and unusual volumes of tenant-domain lookups in sign-in diagnostics

AADOutsider-py is synacktiv's Python3 rewrite of the reconnaissance-as-outsider portion of AADInternals, the well-known PowerShell toolkit for Azure AD and Microsoft 365 research. Where AADInternals is a large framework, this project deliberately narrows its scope to two kill chain functions and all their submethods: Invoke-AADIntReconAsOutsider and Invoke-AADIntUserEnumerationAsOutsider. The value proposition is straightforward — a lightweight, dependency-light Python CLI that consultants can drop onto a Linux box without a PowerShell toolchain. The repo sits at 62 stars, is written in Python, and carries an MIT license, which fits the profile of a practitioner utility rather than a maintained product.


Architecturally, the tool exposes a single entry point, aadoutsider.py, with two positional subcommands: recon and user_enum. Global options control DNS behavior — --dns-tcp forces TCP instead of UDP for DNS requests, --dns lets you pin one or more specific resolvers, and -v toggles verbosity. That DNS plumbing matters operationally because tenant discovery leans heavily on resolving large numbers of candidate domains, and assessors working from restricted egress often need to steer or harden those lookups. The subcommand structure mirrors the original AADInternals cmdlets closely enough that anyone familiar with the PowerShell lineage can map skills directly across.


The recon mode is the heavier of the two. Given a domain via -d/--domain and optionally a username via -u/--username, it enumerates the domains associated with a tenant and reports, per domain, whether DNS, MX, SPF, DMARC, DKIM, and MTA-STS records exist, whether the domain is Managed or Federated, and for federated domains which security token service (STS) handles authentication. It also surfaces tenant-level facts: brand, tenant name such as MicrosoftAPC.onmicrosoft.com, tenant id, region, and whether DesktopSSO is enabled. The -r/--relayingparties flag additionally retrieves relaying parties of the STSs, and -s/--single restricts the run to advanced checks on just the targeted domain.


Output handling is a thoughtful touch for reporting workflows. The -o/--output flag writes results to a file, and -of/--output-form selects between json, csv, and pretty. Anyone who has had to paste a PowerShell table into a client deliverable will appreciate having structured formats built in from the start. The README's sample run against microsoft.com shows the scale the tool can reach — 297 discovered domains in one pass — which is a good reminder that this is fundamentally a bulk OSINT collector against publicly resolvable information.


One important caveat the README makes explicit: recon is flagged with a CAUTION note as patched. Microsoft closed the information disclosure avenues that Invoke-AADIntReconAsOutsider originally abused for part of its discovery, so results in that mode may be degraded or incomplete against current tenants. The user_enum mode, by contrast, remains functional per the documentation. Practitioners should treat the recon subcommand as partially historical and verify current behavior in a lab before relying on it during an engagement.


user_enum validates whether a specific account exists. It takes a username positional argument plus a method selector -m/--method choosing among normal, login, autologon, and rst2, an -e/--external switch, and a -d/--domain option. The four methods correspond to different Microsoft authentication endpoints that historically leaked account existence through differing error responses; having all four in one tool lets an assessor pivot when one channel is rate-limited or returns uniform errors. The README's example shows the canonical outcome: INFO: User [email protected] exists.


Installation is minimal. The README offers either pip3 install git+https://github.com/synacktiv/AADOutsider-py or the conventional route of creating a virtual environment and running pip3 install -r requirements.txt. There is no compiled component, no agent, and no persistence mechanism — everything the tool does happens over outbound HTTPS and DNS from the operator's machine. That keeps the footprint auditable, which is exactly what you want when justifying tooling to a client's change-control process.


Where this fits in an authorized workflow is the pre-engagement and initial-recon phase of a cloud-focused penetration test. Mapping which domains are Federated versus Managed and which STS they delegate to directly informs later attack-surface analysis — federated tenants with third-party IdPs present different token-handling risks than purely managed ones, and mail-security record coverage (SPF, DMARC, DKIM, MTA-STS) feeds into phishing-resilience assessment. Username enumeration then feeds password-spraying scoping decisions, though the tool itself stops cleanly at existence checks and does not attempt authentication.


For defenders, the same tool is a free audit instrument. Running recon and user_enum against your own tenant shows precisely what an unauthenticated outsider can enumerate today: your domain inventory, your federation topology, and whether your identity provider confirms or denies valid usernames. Microsoft has spent years narrowing these oracle behaviors — uniform errors, hidden tenant details — and re-running these checks periodically is a cheap way to verify that hardening actually holds. The documentation links back to aadinternals.com for the underlying research context, which is worth reading for the mechanics of each enumeration method.


The telemetry picture cuts both ways. Because everything here targets public endpoints without credentials, there is no compromise artifact on the victim side, but the patterns are visible: bursts of DNS lookups across a tenant's domain space, and clustered username-validation hits against login and autologon endpoints from a single source. Sign-in logs, identity-protection rules tuned for enumeration, and DNS egress analytics are the natural detection surfaces. An assessor should assume these queries are logged and plan opsec and scoping language accordingly.


In short, AADOutsider-py is a competent, narrowly scoped port of a proven technique set. Its honest labeling of the patched recon path, structured output support, and configurable DNS handling make it more engagement-friendly than scripting the equivalent by hand, while its read-only, unauthenticated nature keeps it firmly in the reconnaissance category rather than anything destructive. For red teamers targeting Microsoft cloud estates and blue teams hardening them, it is a small but useful addition to the toolbox.



Official project repository for synacktiv/AADOutsider-py.

Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.






Source: OffensiveSec
Source Link: https://www.offsecblog.com/2026/09/automating-azure-ad-outsider.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.