# Cloud-Architekt/AzureAD-Attack-Defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

Repository: https://github.com/Cloud-Architekt/AzureAD-Attack-Defense
Canonical: https://ross.abutalabs.com/products/azuread-attack-defense
Language: PowerShell
License Family: other
Topics: azureactivedirectory, itdr, microsoftentraid, microsoftsentinel
Last push: 2026-06-30T12:29:45+00:00

## Health v2 (maintenance only)
Score: 73/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 90, release rhythm 35, longevity 100
- inputs: {"age_days": 2134, "days_push": 64, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2554, forks 367 (observed 2026-08-28T04:07:00.624660+00:00)

## What it is
A community-maintained playbook documenting common attack scenarios against Microsoft Entra ID (Azure AD) with corresponding detection and mitigation guidance. Each chapter maps attack techniques to MITRE ATT&CK and shows how to detect them using the Microsoft security stack.

## Use cases
- learn how password spray attacks on Entra ID are detected and mitigated
- understand adversary-in-the-middle phishing attacks against Azure AD
- detect token replay and PRT theft in Microsoft 365
- secure service principals used in Azure DevOps pipelines
- harden Entra ID consent grant permissions
- map identity attacks to MITRE ATT&CK techniques
- build identity threat detection rules in Microsoft Sentinel
- prevent lateral movement from compromised Active Directory to Entra ID

## When to choose
- you administer or secure a Microsoft Entra ID / Azure AD tenant
- you are building detection rules for identity attacks in Sentinel or Defender
- you want MITRE ATT&CK-mapped guidance for cloud identity threats
- you are preparing for red team or attack simulations against Azure AD

## When to avoid
- you need a runnable security tool rather than documentation (though it references tools like EIDSCA)
- you secure non-Microsoft identity providers like Okta or Keycloak
- you need general on-premises Active Directory hardening unrelated to Entra ID

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, monitoring, documentation
- domain: security, cloud-computing, documentation
- platform: cloud
- tags: entra-id, azure-active-directory, mitre-attack, identity-security, playbook, detection, mitigation, microsoft-sentinel, itdr, web-server

## Member repositories
- Cloud-Architekt/AzureAD-Attack-Defense (main) score 73

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:00.624660+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:23:44.418383+00:00, confidence not recorded.
  - readme: https://github.com/Cloud-Architekt/AzureAD-Attack-Defense (fetched 2026-08-28T04:07:00.624660+00:00, sha f9bb863123dd)
- Data as of 2026-08-30T08:39:29.467469+00:00.
