Enumerate without Credentials - Inside of Virtual Machine
Note: The commands below query unauthenticated public Azure endpoints reachable from anywhere on the internet — they are not specific to being inside an Azure VM. The technique unique to being inside an Azure VM is querying the Instance Metadata Service (IMDS) at
http://169.254.169.254/metadata/(see Section 2 below).
1. Check the getuserrealm.srf endpoint for domain information (External Azure Tenant Recon)
#Check the getuserrealm.srf endpoint for domain information
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=$DOMAIN&json=1" | jq .
#Test if the domain is managed or not
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=$DOMAIN&json=1" | jq .
#Get the NameSpaceType for the domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=$DOMAIN&json=1" | jq -r '.NameSpaceType'
#Check for federation on the domain
curl -s "https://login.microsoftonline.com/getuserrealm.srf?login=$DOMAIN&xml=1"
#Get the TenantID for a managed domain
curl -s "https://login.microsoftonline.com/$DOMAIN/v2.0/.well-known/openid-configuration" | jq -r '.token_endpoint' | cut -d'/' -f4
#Check GetCredentialType endpoint for username enumeration
curl -s -X POST "https://login.microsoftonline.com/common/GetCredentialType" --data "{\"Username\":\"$USERNAME@$DOMAIN\"}" | jq '.IfExistsResult'
2. VM-Internal Enumeration via Instance Metadata Service (IMDS)
The following commands are only reachable from inside an Azure VM (non-routable link-local address):
# Get instance metadata (requires Metadata: true header)
curl -s -H "Metadata: true" "http://169.254.169.254/metadata/instance?api-version=2021-02-01" | jq .
# Get managed identity access token (if VM has a managed identity assigned)
curl -s -H "Metadata: true" "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/" | jq .
# Get subscription and resource group info
curl -s -H "Metadata: true" "http://169.254.169.254/metadata/instance/compute?api-version=2021-02-01" | jq '{subscriptionId, resourceGroupName, vmId, location}'