Entra ID Master Key (EIDMK) icon

Entra ID Master Key (EIDMK)

Bypass Microsoft Entra ID (prev. Azure Active Directory) restrictions and do everything you are allowed to do on CLI but on the UI.

用户数56
评分--
评论数0
Manifest 版本V3
7日增长-6
7日增长率-9.68%
视觉预览

Entra ID Master Key (EIDMK) 媒体预览

3 项素材
趋势

30 日用户趋势

查看最近 30 天的用户变化。

用户增长趋势

55565757582026年5月29日2026年6月1日2026年6月4日最新值: 56
评分趋势

30 日评分变化

按时间查看评分波动,辅助判断近期口碑是否稳定。

评分趋势样本还不够,后续快照会继续补齐。
增长概览

日/周/月增长表现

同口径展示 1 天、7 天、30 天的绝对增长与增长率。

1日增长减少
-2-3.45%
7日增长减少
-6-9.68%
30日增长减少
-9-13.8%
技术摘要

版本、语言与抓取信息

查看发布时间、版本、支持语言、最近更新和抓取时间。

版本1.0
ManifestV3
大小45.19KiB
语言数1English
发布时间
最近更新
最近抓取
English
简介

插件简介

查看插件说明、主要功能和适用场景。

EIDMK allows you to bypass Azure and Microsoft Entra ID portal UI restrictions by tricking your client (web browser) to send (legit and allowed by Microsoft) requests to Microsoft endpoints and thus receiving information that, usually, you would not be allowed to access through UI - but you are 100% allowed by Microsoft to access through CLI, Graph API, PowerShell or any other application/method - which is the case of this extension. Meaning that in fact this is not a bypass, but just another way to retrieve data that you ALREADY have access to. Keep in mind that you do not gain any new permissions by using this extension. Your user keeps exactly same roles, privileges and permissions - as documented here: https://learn.microsoft.com/en-us/entra/fundamentals/users-default-permissions

If you are responsible for managing an Entra ID tentant remember that "Using the Restrict access to Microsoft Entra administration portal switch is NOT a security measure."(https://learn.microsoft.com/en-us/entra/fundamentals/users-default-permissions#restrict-member-users-default-permissions).

It works similar to AzureHound by BloodHoundAD, except you don't need to use a terminal for this and can run it directly on your Google Chrome.

In fact, even Microsoft official documentation states that the UI restriction does not restrict anyone, who has access to a tenant, from retrieving the information from Entra ID - find out more on this article, which was written after reporting to Microsoft a strange UI behaviour on Azure portal: https://www.linkedin.com/pulse/microsoft-azure-active-directory-authorization-bypass-vlad-yultyyev/.

This extension may be handy if you are a security professional who needs a quick solution to analyze Microsoft Entra ID tenant.

You need to be a user of particular tenant to view the content of that tenant.

评价

最新评论快照

查看最近评论和评分分布。

5
0
4
0
3
0
2
0
1
0