Finding the tenant identifier for Azure or Office 365

%3CLINGO-SUB%20id%3D%22lingo-sub-687416%22%20slang%3D%22en-US%22%3ERe%3A%20FindTime%20becomes%20Find%20a%20time%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-687416%22%20slang%3D%22en-US%22%3EYou%20get%20your%20publishing%20mixed%20up%3F%20Body%20doesn't%20match%20the%20subject%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-687421%22%20slang%3D%22en-US%22%3ERe%3A%20FindTime%20becomes%20Find%20a%20time%20in%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-687421%22%20slang%3D%22en-US%22%3ECalled%20%E2%80%9Dclickbait%E2%80%9D%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-686808%22%20slang%3D%22en-US%22%3EFinding%20the%20tenant%20identifier%20for%20Azure%20or%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-686808%22%20slang%3D%22en-US%22%3E%3CP%3E%3CBR%20%2F%3EAfter%20seeing%20a%20tweet%20about%20a%20site%20that%20could%20return%20the%20tenant%20identifier%20for%20any%20Azure%20or%20Office%20365%20tenant%2C%20I%20was%20a%20tad%20suspicious.%20After%20all%2C%20this%20data%20should%20be%20private%20-%20or%20so%20you'd%20think.%20In%20fact%2C%20the%20WhatIsMyTenantId.com%20site%20simply%20takes%20records%20available%20to%20enable%20OAuth%202.0%20sign-ins%20and%20extracts%20the%20tenant%20identifier%20from%20their%20content.%20It's%20an%20easy%20way%20to%20get%20hold%20of%20tenant%20identifiers.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.petri.com%2Ffinding-identifier-azure-office-365-tenants%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fwww.petri.com%2Ffinding-identifier-azure-office-365-tenants%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-686808%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
MVP


After seeing a tweet about a site that could return the tenant identifier for any Azure or Office 365 tenant, I was a tad suspicious. After all, this data should be private - or so you'd think. In fact, the WhatIsMyTenantId.com site simply takes records available to enable OAuth 2.0 sign-ins and extracts the tenant identifier from their content. It's an easy way to get hold of tenant identifiers.

 

https://www.petri.com/finding-identifier-azure-office-365-tenants

2 Replies
You get your publishing mixed up? Body doesn't match the subject :)
Called ”clickbait” :)