Skip to content

Commit

Permalink
improved cpv permissions settings for app perms
Browse files Browse the repository at this point in the history
  • Loading branch information
KelvinTegelaar committed Aug 10, 2023
1 parent b636201 commit 1138265
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 0 deletions.
4 changes: 4 additions & 0 deletions ExecCPVPermissions/run.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,9 @@ $ourSVCPrincipal = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/se

# if the app svc principal exists, consent app permissions
$apps = $ExpectedPermissions
#get current roles
$CurrentRoles = New-GraphGETRequest -uri "https://graph.microsoft.com/beta/servicePrincipals/$($ourSVCPrincipal.id)/appRoleAssignments" -tenantid $tenantfilter
#If
$Grants = foreach ($App in $apps.requiredResourceAccess) {
try {
$svcPrincipalId = New-GraphGETRequest -uri "https://graph.microsoft.com/v1.0/servicePrincipals(appId='$($app.resourceAppId)')" -tenantid $tenantfilter
Expand All @@ -71,6 +74,7 @@ $Grants = foreach ($App in $apps.requiredResourceAccess) {
continue
}
foreach ($SingleResource in $app.ResourceAccess | Where-Object -Property Type -EQ "Role") {
if ($singleresource.id -In $currentroles.appRoleId) { continue }
[pscustomobject]@{
principalId = $($ourSVCPrincipal.id)
resourceId = $($svcPrincipalId.id)
Expand Down
1 change: 1 addition & 0 deletions UpdatePermissionsQueue/run.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,7 @@ $Grants = foreach ($App in $apps.requiredResourceAccess) {
continue
}
foreach ($SingleResource in $app.ResourceAccess | Where-Object -Property Type -EQ "Role") {
if ($singleresource.id -In $currentroles.appRoleId) { continue }
[pscustomobject]@{
principalId = $($ourSVCPrincipal.id)
resourceId = $($svcPrincipalId.id)
Expand Down

0 comments on commit 1138265

Please sign in to comment.