Entra ID Master Key (EIDMK) Chrome 插件, crx 扩展下载
Bypass Microsoft Entra ID (prev. Azure Active Directory) restrictions and do everything you are allowed to do on CLI but on the UI.
EIDMK allows you to bypass Azure and Microsoft Entra ID portal UI restrictions by tricking your client (web browser) to send (legit and allowed by Microsoft) requests to Microsoft endpoints and thus receiving information that, usually, you would not be allowed to access through UI - but you are 100% allowed by Microsoft to access through CLI, Graph API, PowerShell or any other application/method - which is the case of this extension. Meaning that in fact this is not a bypass, but just another way to retrieve data that you ALREADY have access to. Keep in mind that you do not gain any new permissions by using this extension. Your user keeps exactly same roles, privileges and permissions - as documented here: https://learn.microsoft.com/en-us/entra/fundamentals/users-default-permissions If you are responsible for managing an Entra ID tentant remember that "Using the Restrict access to Microsoft Entra administration portal switch is NOT a security measure."(https://learn.microsoft.com/en-us/entra/fundamentals/users-default-permissions#restrict-member-users-default-permissions). It works similar to AzureHound by BloodHoundAD, except you don't need to use a terminal for this and can run it directly on your Google Chrome. In fact, even Microsoft official documentation states that the UI restriction does not restrict anyone, who has access to a tenant, from retrieving the information from Entra ID - find out more on this article, which was written after reporting to Microsoft a strange UI behaviour on Azure portal: https://www.linkedin.com/pulse/microsoft-azure-active-directory-authorization-bypass-vlad-yultyyev/. This extension may be handy if you are a security professional who needs a quick solution to analyze Microsoft Entra ID tenant. You need to be a user of particular tenant to view the content of that tenant. What can you expect to access using this extension? - Exactly same features/information that you can access through Graph API, CLI or PowerShell - List all groups that exist on the tenant - List all users and retrieve their information - List Application Registrations (names, URI, exposed APIs, roles, secret IDs, etc) - List Enterprise applications - List devices (names, operating system version, etc) - Create new tenants (an active Azure subscription is required for this action. Depending on your organization settings, only Azure AD B2C tenants may be allowed)
分类 | 💻开发者工具 |
插件标识 | efnnnegbcgcjcckppnpckhddpfhamegb |
平台 | Chrome |
评分 |
★★★★★
5
|
评分人数 | 6 |
插件主页 | https://chromewebstore.google.com/detail/entra-id-master-key-eidmk/efnnnegbcgcjcckppnpckhddpfhamegb |
版本号 | 1.0 |
大小 | 45.19KiB |
官网下载次数 | 40 |
下载地址 | |
更新时间 | 2024-01-24 00:00:00 |
CRX扩展文件安装方法
第1步: 打开Chrome浏览器的扩展程序
第2步:
在地址栏输入: chrome://extensions/
第3步: 开启右上角的【开发者模式】
第4步: 重启Chrome浏览器 (重要操作)
第5步: 重新打开扩展程序管理界面
第6步: 将下载的crx文件直接拖入页面完成安装
注意:请确保使用最新版本的Chrome浏览器
同类插件推荐
Google Admin Device Search
Highlight an Serial Number or Directory API ID and
Chrome Terminal
A command line interface for chrome.A "termin
[cmd.ms]
Type 'c' <spacebar> and then type in
Graph X-Ray
View Microsoft Graph API and Graph PowerShell info
Entra ID Master Key (EIDMK)
Bypass Microsoft Entra ID (prev. Azure Active Dire
Azure AD App Launcher
Calls the authorize endpoint with minimum required
Azure Portal plus
Add features to Azure PortalAdd the following feat
Azure Authorization Header Extractor
Extracts Azure authorization header from requests*
Cloud Assistant for Developers and DevOps
Cloudureka helps you to improve your cloud instant
Cloudflare Buddy
Create DNS records for your domains added on Cloud
Browser terminal
Extension that allows you to open a native shell i
Multi AI Sidebar
Access to all AI apps like OpenAI ChatGPT, Bing AI
SOCMaster
Get info on OS Commands, IPs, Domains, URLs, Hashe