Private/Resolve-AACTenantId.ps1
|
function Resolve-AACTenantId { <# .SYNOPSIS Returns a tenant's ID (GUID) from its ID or one of its domains (contoso.onmicrosoft.com, contoso.com), from Entra ID's public OpenID metadata - no sign-in needed. .DESCRIPTION A GUID comes back as it is (lower case). A domain is looked up at https://login.microsoftonline.com/<domain>/v2.0/.well-known/openid-configuration, whose issuer carries the tenant ID. A domain no tenant has throws. #> [CmdletBinding()] [OutputType([string])] param( [Parameter(Mandatory)] [string] $Tenant ) $ProgressPreference = 'SilentlyContinue' if ($Tenant -match '^[0-9a-fA-F]{8}(-[0-9a-fA-F]{4}){3}-[0-9a-fA-F]{12}$') { return $Tenant.ToLowerInvariant() } try { $configuration = Invoke-RestMethod -Uri "https://login.microsoftonline.com/$([uri]::EscapeDataString($Tenant))/v2.0/.well-known/openid-configuration" -Method Get -TimeoutSec 30 -ErrorAction Stop -Verbose:$false } catch { $problem = [System.InvalidOperationException]::new("No Entra ID tenant was found for '$Tenant'.") $problem.Data['AACHint'] = 'Use the tenant ID (a GUID) or one of its verified domains, such as contoso.onmicrosoft.com.' throw $problem } $issuer = [string](Get-AACPropertyValue -InputObject $configuration -Name 'issuer') if ($issuer -notmatch '/([0-9a-fA-F]{8}(-[0-9a-fA-F]{4}){3}-[0-9a-fA-F]{12})/') { throw "Entra ID didn't return a tenant ID for '$Tenant'." } $Matches[1].ToLowerInvariant() } |