Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: Collect Eligible Roles and Groups from Azure PIM #49

Closed
wants to merge 3 commits into from

Conversation

youduda
Copy link

@youduda youduda commented Sep 1, 2023

This adds the functionally to collect the eligible roles and eligible groups relations of Azure PIM.
The following Graph API endpoints are used for the collection: Eligible Roles, Eligible Groups. Note: Both endpoints require an explicit admin consent for the required permissions.

The code was tested in a productive environment.

@github-actions
Copy link

github-actions bot commented Sep 1, 2023

CLA Assistant Lite bot All contributors have signed the CLA ✍️ ✅

@youduda
Copy link
Author

youduda commented Sep 1, 2023

I have read the CLA Document and I hereby sign the CLA

@olafhartong
Copy link

This is a great addition!
I've built a similar implementation in a custom tool.
On integration for the UI team, please consider adding a edge type similar to GPLink enforced for the Eligible roles so they stand out better

example:
image

@youduda
Copy link
Author

youduda commented Sep 24, 2023

I already created an implementation for the UI that adds the new edge type similar to what you suggested, see here.

@irshadaj irshadaj added the external This pull request is from an external contributor label Sep 11, 2024
@AlexanderDeBattista
Copy link

Are there any intentions to merge this PR? Have been missing this feature for a long time. :)

@StephenHinck
Copy link
Collaborator

This PR would require a corroborating BloodHound PR to support adding the new edges. Our team has been working internally on a more fully functional version of this effort, including approvals processes. Expect to see that in the near future.

@youduda - thank you for the contribution. If you would be interested in a swag package, we would happily send you one to show our appreciation. Please email me at shinck [AT] specterops [DOT] io.

@github-actions github-actions bot locked and limited conversation to collaborators Nov 13, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
external This pull request is from an external contributor
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants