byt3bl33d3r/SprayingToolkit

Atomizer is showing valid credentials when actually failing

qgrosperrin opened this issue · 2 comments

The message returned by Lync sprayer is invalid in some scenarios where the following message is returned in the SOAP response for the authentication request:

AADSTS50034: The user account Microsoft.AzureAD.Telemetry.Diagnostics.PII does not exist in the <domain> directory. To sign into this application, the account must be added to the directory.

The tool actually prints "Found credentials:... " in that case.

Good to know, i'll update it when i can.
Cheers

I'm also getting this error on an engagement. Just wondering what the test case is here - as it might seem that the client is in the process of transitioning to the o365 environment.