Getting the first token into an Entra tenant is an outside-in problem: learn which users exist and how the tenant authenticates, then obtain a credential or token without tripping lockout or conditional access. Everything here produces an access or refresh token that the rest of the Entra surfaces consume.
What folds in here#
- Enumeration: unauthenticated user, tenant, and federation discovery.
- Password spraying: guessing credentials against the sign-in endpoints within Smart Lockout.
- Device code phishing: phishing the OAuth device-code flow for tokens.
- Primary refresh token: stealing and replaying the PRT from a joined device.
- Conditional access: slipping past conditional-access policies.
- MFA bypass: defeating or enrolling multi-factor methods.
- Token theft: harvesting and replaying access and refresh tokens.