Private/30a-GetAtlasConsent.ps1
|
function Get-AtlasConsent { [CmdletBinding()] param([string] $TenantId, [AllowEmptyCollection()] [AtlasNode[]] $KnownNode) $result = [AtlasCollectionResult]::new() $lookup = @{} foreach ($node in $KnownNode) { $lookup[$node.Id] = $node } $endpoint = '/v1.0/oauth2PermissionGrants' $response = Invoke-AtlasGraphRequest -Uri $endpoint foreach ($grant in $response.Items) { if (-not $grant.id -or -not $grant.clientId -or -not $grant.resourceId -or $grant.consentType -notin @('Principal', 'AllPrincipals')) { $result.Status = 'partial' $result.Warnings.Add('A delegated consent record was incomplete or had an unsupported consent type.') continue } foreach ($referenceId in @($grant.clientId, $grant.resourceId, $grant.principalId) | Where-Object { $_ }) { if (-not $lookup.ContainsKey($referenceId)) { $kind = if ($referenceId -eq $grant.principalId) { 'user' } else { 'servicePrincipal' } $placeholder = New-AtlasNode -TenantId $TenantId -Id $referenceId -Kind $kind -DisplayName $referenceId -Status unresolved -Source @{ collector = 'delegatedConsent' } $result.Nodes.Add($placeholder) $lookup[$referenceId] = $placeholder $result.Status = 'partial' $result.Warnings.Add('A delegated consent reference could not be resolved from collected objects.') } } if ($grant.consentType -eq 'Principal' -and -not $grant.principalId) { $result.Status = 'partial' $result.Warnings.Add('A user-specific consent record has no principal identifier.') continue } $fields = @{ consentType = $grant.consentType; clientId = $grant.clientId; resourceId = $grant.resourceId; principalId = $grant.principalId; scope = $grant.scope } $evidence = New-AtlasEvidence -TenantId $TenantId -Collector 'delegatedConsent' -Endpoint $endpoint -SourceObjectId $grant.id -Fields $fields $result.Evidence.Add($evidence) $audience = if ($grant.consentType -eq 'AllPrincipals') { 'All users' } else { 'Specific user' } $node = New-AtlasNode -TenantId $TenantId -Id "oauth2PermissionGrant:$($grant.id)" -Kind oauth2PermissionGrant -DisplayName "$audience delegated consent: $($lookup[$grant.clientId].DisplayName)" -Properties $fields -Source @{ collector = 'delegatedConsent'; resourcePath = "$endpoint/$($grant.id)"; provider = 'microsoftGraph'; apiVersion = 'v1.0' } $result.Nodes.Add($node) $result.Edges.Add((New-AtlasEdge -TenantId $TenantId -From $lookup[$grant.clientId].Key -To $node.Key -Relationship hasDelegatedConsent -State $fields -EvidenceIds @($evidence.Key) -Source @{ collector = 'delegatedConsent' })) $result.Edges.Add((New-AtlasEdge -TenantId $TenantId -From $node.Key -To $lookup[$grant.resourceId].Key -Relationship grantsDelegatedScopes -State $fields -EvidenceIds @($evidence.Key) -Source @{ collector = 'delegatedConsent' })) if ($grant.consentType -eq 'Principal') { $result.Edges.Add((New-AtlasEdge -TenantId $TenantId -From $lookup[$grant.principalId].Key -To $node.Key -Relationship subjectOfDelegatedConsent -State $fields -EvidenceIds @($evidence.Key) -Source @{ collector = 'delegatedConsent' })) } } $result.Metrics = @{ grantCount = $response.Items.Count; requestCount = $response.Metrics.requestCount; retryCount = $response.Metrics.retryCount } return $result } |