> For the complete documentation index, see [llms.txt](https://tools.thehacker.recipes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://tools.thehacker.recipes/mimikatz/modules/sekurlsa/cloudap.md).

# cloudap

`sekurlsa::cloudap` lists Azure (Primary Refresh Token) credentials based on the following research: [Digging further into the Primary Refresh Token](https://dirkjanm.io/digging-further-into-the-primary-refresh-token/). [According to Benjamin](https://twitter.com/gentilkiwi/status/1291102498099527682?s=20):

* Azure API does not verify ctx replay
* Azure relies on symmetric keys
* Software or TPM keys are "protected" by legacy DPAPI
* AzureAd logon must support device key for legacy DPAPI

{% hint style="warning" %}
This command requires elevated privileges (by previously running [`privilege::debug`](/mimikatz/modules/privilege/debug.md) or by executing Mimikatz as the `NT-AUTHORITY\SYSTEM` account).
{% endhint %}

```
mimikatz # sekurlsa::cloudap
```

The following screenshot was borrowed from [this tweet](https://twitter.com/_dirkjan/status/1290397176561119233):

![Azure session key dump](https://894632015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MiRT0QHotSpofwDFs_w%2Fuploads%2Fgit-blob-25d5dee0df69c619d00d43b32747670aa17c65fb%2F2.png?alt=media)
