Public/Get-GraphConnectionCommand.ps1
|
function Get-GraphConnectionCommand { <# .SYNOPSIS Returns a delegated Connect-MgGraph command for each least-privilege scope and operation. .DESCRIPTION Permission alternatives are returned separately, never combined into a broader scope set. Does not connect or execute the generated command. Application authentication does not use -Scopes. .EXAMPLE Get-GraphConnectionCommand -Cmdlet Get-MgUser -Endpoint /users #> [CmdletBinding()] [OutputType('GraphShell.ConnectionCommand')] param( [Parameter(Mandatory, ValueFromPipeline)][string]$Cmdlet, [ValidateSet('DelegatedWork','DelegatedPersonal')][string]$PermissionType = 'DelegatedWork', [string]$Endpoint, [ValidateSet('v1.0','beta')][string]$ApiVersion = 'v1.0' ) process { $mappings = @(Get-GraphMapping -Cmdlet $Cmdlet -IncludeDetails | Where-Object { $_.ApiVersion -eq $ApiVersion -and (-not $Endpoint -or $_.Endpoint -eq $Endpoint) }) $found = $false foreach ($mapping in $mappings) { foreach ($permission in @($mapping.Permissions | Where-Object { $_.IsLeastPrivilege -eq $true -and $_.PermissionType -eq $PermissionType } | Sort-Object Name -Unique)) { $found = $true [pscustomobject]@{ PSTypeName = 'GraphShell.ConnectionCommand' Cmdlet = $mapping.Cmdlet Endpoint = $mapping.Endpoint Method = $mapping.Method ApiVersion = $mapping.ApiVersion PermissionType = $PermissionType Scope = $permission.Name Command = "Connect-MgGraph -Scopes '$($permission.Name.Replace("'", "''"))'" } } } if (-not $found) { Write-Warning "No least-privilege delegated scope is recorded for '$Cmdlet' and the selected operation." } } } |