Labs · IAM Toolkit

IAM Toolkit

Practical identity security tools I'd want on a real engagement: audit scripts for Entra ID and Active Directory, a token inspector, strong secrets, and a hands-on look at MFA and passkeys.

🔒 Everything except the prompt-injection lab runs in your browser. Nothing you paste or generate is sent to this site.

PowerShell & Graph script generator

Audit scripts for Entra ID and Active Directory: stale accounts, expiring app secrets, privileged roles, MFA gaps, risky app permissions.

Entra ID ¡ Active Directory ¡ PowerShell

JWT inspector

Decode an access or ID token and flag the risky parts: alg none, no expiry, missing audience, broad scopes. Verify the signature too.

OAuth ¡ OIDC ¡ Entra tokens

Password & passphrase generator

Strong passphrases and random secrets from your browser's secure generator, with presets for users, service accounts and break-glass.

Passwords ¡ Secrets ¡ NIST

MFA & passkey playground

Scan a demo QR code with your authenticator app and watch the codes work, then create a passkey and see why it resists phishing.

MFA ¡ TOTP ¡ Passkeys

Prompt-injection lab

Try to trick a sandboxed AI helpdesk agent into leaking a secret or misusing a tool, against three levels of defence.

AI agents ¡ Prompt injection ¡ MCP

Graph permission risk checker

Paste app permissions, scopes or a token and get a risk rating for each, with least-privilege alternatives.

Microsoft Graph ¡ App consent ¡ Least privilege

Conditional Access explainer

Paste a policy export and get each policy in plain English, the risky settings, and what your set does and doesn't cover.

Entra ID ¡ Conditional Access ¡ Zero trust

Non-human identity scorecard

Ten questions about your service accounts, app credentials and AI agents, and a short report on where the risk is.

Service accounts ¡ Workload identity ¡ AI agents

Want this done properly across your estate? See how I work with teams →