Guest access

A B2B guest is an external identity given an object inside the target tenant. Guests are often under-restricted: they can enumerate users, groups, and applications, and in permissive tenants reach data and even escalate toward member-equivalent access. A guest foothold is a cheap way inside a tenant you do not own.

Enumerate as a guest#

bash
# authenticated as a guest, enumerate the directory (default guest permissions often allow this)
az rest --method GET --url "https://graph.microsoft.com/v1.0/users?\$top=999"
az rest --method GET --url "https://graph.microsoft.com/v1.0/groups"
# roadrecon runs a full guest-scoped dump
roadrecon gather

Exploitation notes#

  • Default guest permissions in many tenants allow broad read of users, groups, and apps, which maps the whole attack surface from outside.
  • Guests can own or be added to groups and apps, which opens group and application edges that escalate toward member access.
  • Invitation is low-friction: an accepted invite plants the guest object; redemption can sometimes be pre-empted to take the account.

Tools#

  • ROADtools (roadrecon): guest-scoped directory enumeration.
  • az cli / Graph.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more