Going for Broke(ring) – Offensive Walkthrough for Nested App Authentication
ID: a033ec05-d782-5037-aa14-1c9f7b88427a
STIX ID: report--a033ec05-d782-5037-aa14-1c9f7b88427a
Feed Name: SpecterOps Blog
The report explains Microsoft’s Nested App Authentication (NAA, aka BroCI) and how refresh tokens from administrator portals can be brokered to obtain tokens for other Microsoft services, often preserving MFA claims. It outlines the minimal parameters for brokered OAuth requests and demonstrates offensive use cases—retrieving Conditional Access Policies, activating PIM roles, accessing Azure Key Vault secrets, and listing Intune devices—using tools such as EntraTokenAid, ROADtools/roadtx, and SpecterOps Maestro, noting that the method relies on refresh tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
