Summary Adds a tenant-scoped Entra Groups “Directory Cache” to enable DB-only group name resolution across the app (no render-time Graph calls), plus sync runs + observability. What’s included • Entra Groups cache • New entra_groups storage (tenant-scoped) for group metadata (no memberships). • Retention semantics: groups become stale / retained per spec (no hard delete on first miss). • Group Sync Runs • New “Group Sync Runs” UI (list + detail) with tenant isolation (403 on cross-tenant access). • Manual “Sync Groups” action: creates/reuses a run, dispatches job, DB notification with “View run” link. • Scheduled dispatcher command wired in console.php. • DB-only label resolution (US3) • Shared EntraGroupLabelResolver with safe fallback Unresolved (…last8) and UUID guarding. • Refactors to prefer cached names (no typeahead / no live Graph) in: • Tenant RBAC group selects • Policy version assignments widget • Restore results + restore wizard group mapping labels Safety / Guardrails • No render-time Graph calls: fail-hard guard test verifies UI paths don’t call GraphClientInterface during page render. • Tenant isolation & authorization: policies + scoped queries enforced (cross-tenant access returns 403, not 404). • Data minimization: only group metadata is cached (no membership/owners). Tests / Verification • Added/updated tests under tests/Feature/DirectoryGroups and tests/Unit/DirectoryGroups: • Start sync → run record + job dispatch + upserts • Retention purge semantics • Scheduled dispatch wiring • Render-time Graph guard • UI/resource access isolation • Ran: • ./vendor/bin/pint --dirty • ./vendor/bin/sail artisan test tests/Feature/DirectoryGroups • ./vendor/bin/sail artisan test tests/Unit/DirectoryGroups Notes / Follow-ups • UI polish remains (picker/lookup UX, consistent progress widget/toasts across modules, navigation grouping). • pr-gate checklist still has non-blocking open items (mostly UX/ops polish); requirements gate is green. Co-authored-by: Ahmed Darrazi <ahmeddarrazi@adsmac.local> Reviewed-on: #57
123 lines
5.6 KiB
PHP
123 lines
5.6 KiB
PHP
<?php
|
|
|
|
return [
|
|
'permissions' => [
|
|
[
|
|
'key' => 'DeviceManagementConfiguration.ReadWrite.All',
|
|
'type' => 'application',
|
|
'description' => 'Read and write Intune device configuration policies.',
|
|
'features' => ['policy-sync', 'backup', 'restore', 'settings-normalization'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementConfiguration.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read Intune device configuration policies (least-privilege for inventory).',
|
|
'features' => ['policy-sync', 'backup', 'settings-normalization'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementApps.ReadWrite.All',
|
|
'type' => 'application',
|
|
'description' => 'Manage app configuration and assignments for Intune.',
|
|
'features' => ['backup', 'restore'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementApps.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read app configuration and assignments for Intune.',
|
|
'features' => ['policy-sync', 'backup'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementServiceConfig.ReadWrite.All',
|
|
'type' => 'application',
|
|
'description' => 'Manage enrollment restrictions, Autopilot, ESP, and related service configs.',
|
|
'features' => ['backup', 'restore', 'policy-sync'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementServiceConfig.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read enrollment restrictions, Autopilot, ESP, and related service configs.',
|
|
'features' => ['policy-sync', 'backup'],
|
|
],
|
|
[
|
|
'key' => 'Policy.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read Conditional Access policies for preview/backup.',
|
|
'features' => ['conditional-access', 'backup', 'versioning'],
|
|
],
|
|
[
|
|
'key' => 'Policy.ReadWrite.ConditionalAccess',
|
|
'type' => 'application',
|
|
'description' => 'Manage Conditional Access policies (used for preview-only or admin-controlled restores).',
|
|
'features' => ['conditional-access', 'restore'],
|
|
],
|
|
[
|
|
'key' => 'Directory.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read directory data needed for tenant health checks.',
|
|
'features' => ['tenant-health'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementRBAC.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read Intune RBAC settings including scope tags for backup metadata enrichment.',
|
|
'features' => ['scope-tags', 'backup-metadata', 'assignments'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementRBAC.ReadWrite.All',
|
|
'type' => 'application',
|
|
'description' => 'Manage Intune RBAC scope tags for foundation backup and restore.',
|
|
'features' => ['scope-tags', 'foundations', 'backup', 'restore'],
|
|
],
|
|
[
|
|
'key' => 'Group.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read group information for resolving assignment group names and cross-tenant group mapping.',
|
|
'features' => ['assignments', 'group-mapping', 'backup-metadata', 'directory-groups', 'group-directory-cache'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementScripts.ReadWrite.All',
|
|
'type' => 'application',
|
|
'description' => 'Manage Intune device management scripts and remediations.',
|
|
'features' => ['policy-sync', 'backup', 'restore', 'scripts', 'remediations'],
|
|
],
|
|
[
|
|
'key' => 'DeviceManagementScripts.Read.All',
|
|
'type' => 'application',
|
|
'description' => 'Read Intune device management scripts and remediations.',
|
|
'features' => ['policy-sync', 'backup', 'scripts', 'remediations'],
|
|
],
|
|
],
|
|
// Stub list of permissions already granted to the service principal (used for display in Tenant verification UI).
|
|
// Diese Liste sollte mit den tatsächlich in Entra ID granted permissions übereinstimmen.
|
|
// HINWEIS: In Produktion sollte dies dynamisch von Graph API abgerufen werden (geplant für v1.1+).
|
|
//
|
|
// ⚠️ WICHTIG: Nach dem Hinzufügen neuer Berechtigungen in Azure AD:
|
|
// 1. Berechtigungen in Azure AD hinzufügen und Admin Consent geben
|
|
// 2. Diese Liste unten aktualisieren (von "Required permissions" nach "Tatsächlich granted" verschieben)
|
|
// 3. Cache leeren: php artisan cache:clear
|
|
// 4. Optional: Live-Check auf Tenant-Detailseite ausführen
|
|
'granted_stub' => [
|
|
// Tatsächlich granted (aus Entra ID):
|
|
'Device.Read.All',
|
|
'DeviceManagementConfiguration.Read.All',
|
|
'DeviceManagementConfiguration.ReadWrite.All',
|
|
'DeviceManagementManagedDevices.ReadWrite.All',
|
|
'DeviceManagementServiceConfig.Read.All',
|
|
'Directory.Read.All',
|
|
'User.Read',
|
|
'DeviceManagementScripts.ReadWrite.All',
|
|
|
|
// Feature 004 - Assignments & Scope Tags (granted seit 2025-12-22):
|
|
'DeviceManagementRBAC.Read.All', // Scope Tag Namen auflösen
|
|
'Group.Read.All', // Group Namen für Assignments auflösen
|
|
|
|
// Required permissions (müssen in Entra ID granted werden):
|
|
// Wenn diese fehlen, erscheinen sie als "missing" in der UI
|
|
'DeviceManagementApps.ReadWrite.All',
|
|
'DeviceManagementApps.Read.All',
|
|
'DeviceManagementServiceConfig.ReadWrite.All',
|
|
'Policy.Read.All',
|
|
'Policy.ReadWrite.ConditionalAccess',
|
|
],
|
|
];
|