Microsoft Teams Account Enumeration
Discover which email addresses in your domain correspond to active Microsoft 365 identities using Guard's Teams account enumeration capability.
Overview
Organizations using Microsoft Teams expose an account enumeration surface that adversaries routinely probe to map valid employees before phishing or credential-stuffing campaigns. Guard's Microsoft Teams Account Enumeration capability generates candidate email addresses for a target domain and probes each address through the Microsoft Teams presence API, identifying which addresses correspond to live Microsoft 365 identities — giving your team the attacker's view before adversaries get it.
Discovered accounts surface as findings tied to the owning asset in Guard's attack surface graph.
How It Works
- Guard's built-in enumeration engine generates candidate email addresses for the configured domain.
- Each candidate is probed through the Microsoft Teams presence API.
- Valid accounts — those confirmed as active Microsoft 365 identities — are surfaced as findings linked to the associated Organization asset.
No authentication to the target tenant is required to determine account existence. Guard acquires credentials once per tenant using a Microsoft Entra device-code flow; tokens are scoped and stored per customer tenant, so no persistent passwords are retained.
Key Capabilities
Get Started
- In Guard, navigate to Integrations > OSINT > Microsoft Teams.
- Follow the wizard to authenticate with your Microsoft account using the device-code flow displayed on screen.
- Once authenticated, Guard begins enumerating accounts for the configured domain. Results appear as findings under the associated Organization asset.
Findings
Valid accounts identified during enumeration are recorded as findings tied to the Organization asset that owns the domain. Each finding represents a confirmed Microsoft 365 identity and provides the basis for downstream analysis such as phishing simulation or credential-attack testing.
Notes
- The capability operates against the domain configured for your Guard organization. Ensure the target domain is registered as an asset before running enumeration.
- The device-code token is stored per tenant and refreshed automatically; re-authentication is only required if the token is revoked or expires beyond the refresh window.
- Account enumeration does not require — and does not attempt — access to the target tenant's administrative interfaces.