logo

Going for Broke(ring) – Offensive Walkthrough for Nested App Authentication

ID: a033ec05-d782-5037-aa14-1c9f7b88427a

STIX ID: report--a033ec05-d782-5037-aa14-1c9f7b88427a

Feed Name: SpecterOps Blog

Date Published: 2025-08-13

Date Updated: 2026-04-30

Author: Hope Walker

...
...

The report explains Microsoft’s Nested App Authentication (NAA, aka BroCI) and how refresh tokens from administrator portals can be brokered to obtain tokens for other Microsoft services, often preserving MFA claims. It outlines the minimal parameters for brokered OAuth requests and demonstrates offensive use cases—retrieving Conditional Access Policies, activating PIM roles, accessing Azure Key Vault secrets, and listing Intune devices—using tools such as EntraTokenAid, ROADtools/roadtx, and SpecterOps Maestro, noting that the method relies on refresh tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.