Module 6 Links and Resources Legacy Auth Deprecation: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/deprecation-of-basic-authentication-exchange-online MSOLSpray: https://github.com/dafthack/MSOLSpray PynAuth: https://github.com/Synzack/PynAuth Application Permissions (OAuth): https://learn.microsoft.com/en-us/graph/permissions-reference Graph API Documentation: https://learn.microsoft.com/en-us/graph/api/user-get?view=graph-rest-1.0&tabs=http Microsoft Publisher Verification: https://learn.microsoft.com/en-us/azure/active-directory/develop/publisher-verification-overview ___________________ DEVICE CODE AUTHENTICATION: @DrAzureAD Blog - Device Code Authentication: https://aadinternals.com/post/phishing/#new-phishing-technique-device-code-authentication Client IDs (MSFT): https://learn.microsoft.com/en-us/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in Device Login URL: https://microsoft.com/devicelogin POST Request to: https://login.microsoftonline.com/Common/oauth2/token?api-version=1.0 GRAPH API - Get Users: https://learn.microsoft.com/en-us/graph/api/user-list?view=graph-rest-1.0&tabs=http ___________________ BUSINESS EMAIL COMPROMISE: Graph Explorer: https://developer.microsoft.com/en-us/graph/graph-explorer Microsoft Graph SDK: https://learn.microsoft.com/en-us/powershell/microsoftgraph/get-started?view=graph-powershell-1.0 Graph API: https://learn.microsoft.com/en-us/graph/api/overview?view=graph-rest-1.0 For a full list of operations logged in audit logs: https://learn.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwide Full list of permissions in eDiscovery auditing https://learn.microsoft.com/en-us/microsoft-365/compliance/search-for-ediscovery-activities-in-the-audit-log?view=o365-worldwide Exchange Admin Portal: https://admin.microsoft.com/AdminPortal/Home?#/users Disable Forwarding Rules: https://security.microsoft.com/