What problem does it solve?
This Skill solves the challenge of conducting safe, effective authorized red team operations against Microsoft 365 and Entra ID environments, including credential validation, user enumeration, and Conditional Access assessment, while avoiding accidental account lockouts, false positive validations, and unnecessary detection risk.
Core Features & Use Cases
- AADSTS Error Code Reference: Quickly distinguish between invalid credentials, valid credentials blocked by MFA/Conditional Access, locked accounts, and non-existent users to avoid wasted effort and false positives.
- Smart Lockout Discipline: Built-in attempt caps and state tracking ensure password sprays never trigger Microsoft's Smart Lockout policies, preventing accidental disruption of production user accounts.
- Lockout Differential Detection: Identify active external password spray campaigns targeting the tenant by analyzing pre-existing locked accounts during your engagement.
- Use Case: For an authorized engagement testing a client's M365 environment, use this Skill to safely validate leaked credentials from stealer logs, identify functional accounts that may be exempt from MFA, and detect if an external attacker is already actively targeting the tenant.
Quick Start
Use the m365-entra-attack skill to safely validate a list of corporate email addresses against a known password list for an authorized M365 red team engagement, tracking per-user attempt counts to avoid triggering Smart Lockout policies.