Abstract
Azure Activedirectory Library For Android is an open-source Cybersecurity & Ethical Hacking project. The ADAL SDK for Android gives you the ability to add support for Work Accounts to your application with just a few lines of additional code. This SDK gives your application the full functionality of Microsoft Azure AD, including industry standard protocol support for OAuth2, Web API integration with user level consent, and two factor authentication support. ADAL for Android gives you the ability to add support for Work Accounts to your application. This SDK gives your application the full functionality of Microsoft Azure AD, including industry standard protocol support for OAuth2, Web API integration with user level consent, and two-factor authentication support. It is built using Java. Key capabilities include: Industry standard Oauth2 protocol support; Id Token exposure for full access to the token contents; Multi-resource refresh token allows for apps registered together to access different APIs without prompting the user. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
ADAL for Android gives you the ability to add support for Work Accounts to your application. This SDK gives your application the full functionality of Microsoft Azure AD, including industry standard protocol support for OAuth2, Web API integration with user level consent, and two-factor authentication support. Best of all, it’s FOSS (Free and Open Source Software) so that you can participate in the development process as we build these libraries.
A Work Account is an identity you use to get work done from your organization or school. Anywhere you need to get access to your work life you'll use a Work Account. The Work Account can be tied to an Active Directory server running in your datacenter or live completely in the cloud like when you use Office 365. A Work Account will be how your users know that they are accessing their important documents and data backed my Microsoft security.
- 2.0-alpha (released 2015-07-27) - 2.0.1-alpha (released 2015-09-25) - 2.0.2-alpha (released 2016-05-27) - 2.0.3-alpha (released 2016-06-11) - 2.0.4-alpha (released 2017-02-17)
2. Objective
The ADAL SDK for Android gives you the ability to add support for Work Accounts to your application with just a few lines of additional code. This SDK gives your application the full functionality of Microsoft Azure AD, including industry standard protocol support for OAuth2, Web API integration with user level consent, and two factor authentication support.
This project demonstrates how Java can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Industry standard Oauth2 protocol support.
- Id Token exposure for full access to the token contents.
- Multi-resource refresh token allows for apps registered together to access different APIs without prompting the user.
- Cache with Encryption for easily accessing existing tokens and session state with assurance it wasn't tampered with.
- Support for the Microsoft Azure AD Authenticator plug-in for Android, which will be released soon!
- Dialog and Fragment support
4. Technology Stack
- Follow the Prerequisites
- Add a reference to your project and specify it as an Android library. If you are uncertain how to do this, click here for more information.
- Add the project dependency for debugging in to your project settings
- Update your project's AndroidManifest.xml file to include:
- NOTE: You need to write down the APP ID URI for the next steps
- Register your client native app at AAD. Select webapis in the list and give permission to previously registered WebAPI. If you need help with this step, see: Register the REST API Service Windows Azure Active Directory
- NOTE: You will need to write down the clientId and redirectUri parameters for the next steps.
- NOTE: mContext is a field in your activity
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- JDK 11 or later
- Maven / Gradle
- IntelliJ IDEA, Eclipse or Android Studio
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/AzureAD/azure-activedirectory-library-for-android.git
cd azure-activedirectory-library-for-android- Clone this repo in to a directory of your choice
- Setup emulator with SDK 23
- Go to the root folder where you cloned this repo
- To run the sample app, connect the test device and run the command: ./gradlew installDebug
- You should see app 'Fancy ADAL Test App' installed on the test device
- Select an authority, [optionally] enter a login hint and/or query parameters, and click Acquire Token to enter credentials with AAD
- Clone this repo in to a directory of your choice
- Follow the steps at Prerequisites section to setup your maven for android
Full setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by AzureAD and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship