Entra authentication produces bearer tokens, and a bearer token is enough on its own: steal an access or refresh token from a host and replay it, no password or MFA required. Refresh tokens are the prize because they mint fresh access tokens, often across multiple first-party resources.
Where tokens live and how to replay#
# token caches on disk / in memory
# Az CLI: ~/.azure/msal_token_cache.json / accessTokens.json
# Az PowerShell: TokenCache.dat
# browser: ESTSAUTH / ESTSAUTHPERSISTENT cookies, and the token cache of Teams/Office
# replay a stolen refresh token for new access tokens with TokenTactics
Invoke-RefreshToMSGraphToken -refreshToken <rt> -domain example.com
Invoke-RefreshToAzureManagementToken -refreshToken <rt> -domain example.com
Exploitation notes#
- A refresh token from a broad first-party client (for example the Az CLI) exchanges across Graph, Azure management, and other resources, widening a single theft.
- Tokens carry the original MFA and device claims, so replay inherits them and passes conditional access that trusts those claims.
- Access tokens are short-lived (roughly an hour); grab the refresh token for persistence.
Tools#
- TokenTactics (
Invoke-RefreshTo*): refresh-token exchange across resources. - ROADtools (
roadtx): token handling and refresh. - AADInternals: cache extraction and token use.