logo

Unwelcome Guest: Abusing Azure Guest Access to Dump…

ID: 71d6b604-befb-5855-a0c9-62b8e0643c0b

STIX ID: report--71d6b604-befb-5855-a0c9-62b8e0643c0b

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report demonstrates a reconnaissance technique against Azure AD tenants where a guest account (with default external collaboration settings) can programmatically enumerate users, groups, group memberships, and applications by discovering ObjectIds and using PowerShell and Microsoft Graph calls; the author provides a proof-of-concept script, discusses attack methodology and automation, and recommends restricting guest permissions as remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.