logo

Requesting Azure AD Request Tokens

ID: 76d8a46f-5d5f-5cf9-a904-9f6fe449fe3c

STIX ID: report--76d8a46f-5d5f-5cf9-a904-9f6fe449fe3c

Feed Name: SpecterOps Blog

Date Published: 2020-07-14

Date Updated: 2026-04-30

Author: Bloodhound Team

...
...

This research details how Windows 10 Accounts/BrowserCore and the MicrosoftAccountTokenProvider COM interface can be leveraged to obtain Azure AD refresh tokens and perform SSO impersonation on Azure AD–joined Windows hosts, then provides defensive telemetry (e.g., MicrosoftAccountTokenProvider.dll load patterns and a specific ETW provider GUID with example trace events) to detect such abuse, underscoring the importance of monitoring new credential sources on Azure AD–integrated endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.