Conditional-access policies gate sign-in on conditions (app, platform, location, device state), and bypasses come from the gaps between those conditions. If a policy targets only certain apps or platforms, you present as something it does not cover; if it trusts a device-compliance or location signal, you spoof or enter from it.
Finding and slipping the gaps#
# present a device platform / client the policy does not cover by changing the user-agent
# (e.g. a policy that blocks mobile but not a spoofed desktop or legacy client)
curl -s -A "Mozilla/5.0 (Windows NT 10.0)" https://login.microsoftonline.com/...
# legacy-auth endpoints (Exchange ActiveSync, Autologon) often fall outside modern-auth CA
Enumerate policies once you hold a token (roadrecon dumps CA policies) and read them for the uncovered app, platform, or client-type.
Exploitation notes#
- Legacy authentication protocols are the classic hole: many policies only apply to modern auth, so basic-auth endpoints bypass them.
- A policy requiring a compliant or hybrid-joined device is defeated by registering or forging such a device (see device registration).
- Location-based policies trust source IP; a VPN or egress in an allowed range satisfies them.
Tools#
- ROADtools (
roadrecon): dump and analyse CA policies. - AADInternals / TokenTactics: authenticate through alternate endpoints.