
Cracken + Microsoft Entra ID
Cracken lists the users and groups in your tenant through a read-only Microsoft Entra ID app registration. It works those identities toward Global Administrator to prove which escalation paths hold.
Connecting Microsoft Entra ID
- Connect with
Directory Tenant ID, application Client ID and client-secret value for a single-tenant Entra app registration holding the Microsoft Graph application permissions User.Read.All and Group.Read.All, with tenant-wide admin consent granted.
- Cadence
Syncs on a schedule — every 6 hours by default for a hosted connection.
- Requires
Permission to create an app registration and client secret, plus an administrator who can grant consent for Microsoft Graph application permissions.
What Cracken gets from Microsoft Entra ID
Users in your Entra ID tenant, read through the List Users action and paged 100 at a time
Groups in your tenant, read through the List Groups action, so Cracken knows which identity sits where
What Microsoft Entra ID does not do
Cracken only reads from Microsoft Entra ID: it cannot create, disable or reset a user, and it cannot change a group. Identity records never become Cybergraph nodes either — users and groups are listed, not mapped into the graph.
How Cracken uses Microsoft Entra ID
- 01
Register an application in your tenant
- 02
Map the tenant's identities
- 03
Work the paths toward Global Administrator
- 04
Confirm it connected
Frequently asked questions
What permissions does Cracken need in Microsoft Entra ID?
Authenticating as a registered application, Cracken calls only list users and list groups, so directory read permissions like User.Read.All and Group.Read.All suffice.
Does Cracken modify identities in Microsoft Entra ID?
No; Cracken only reads users and groups, creating no accounts, changing no role assignments or Conditional Access policy, and resetting no credentials.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations
Okta
Cracken reads Okta users and groups live into the identity map it attacks.

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Attack with real Microsoft Entra ID context.
See how Cracken works what Microsoft Entra ID already knows into attack paths it proves end to end.

