Get-MgBetaNetworkAccessForwardingPolicyRule Returns 200 OK with Empty Value [] for Policies with Existing Rules
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- powershell
- Área
- api
Línea de trabajo
Comienza reproduciendo Get-MgBetaNetworkAccessForwardingPolicyRule con el ID de la política de reenvío indicado e inspecciona la respuesta de GET /beta/networkAccess/forwardingPolicies/{id}/policyRules. Compara el array de valores vacío con los segmentos de aplicación existentes de la política en el Microsoft Entra admin center; se considera terminado cuando se devuelven las reglas configuradas, incluidos los datos disponibles de IP, FQDN, puerto y protocolo, o cuando se identifica claramente el comportamiento del SDK.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
When querying for the rules of a specific, valid forwarding policy ID using Get-MgBetaNetworkAccessForwardingPolicyRule, the Graph API successfully returns a 200 OK status code. However, the body of the response incorrectly contains an empty value array ("value": []), even when the policy has numerous rules (application segments) visible in the Microsoft Entra admin center.
This behavior makes it impossible to automate the enumeration of all FQDNs and IP ranges within Private Access, as the API is not returning the configured data.
Expected behavior
List the rules for the policy? Display the IP and FQDN, possibly the Ports and protocol.
How to reproduce
Connect-MgGraph -Scopes "NetworkAccess.Read.All"
# Get all policies and select one for testing
$policies = Get-MgBetaNetworkAccessForwardingPolicy | Where-Object { $_.TrafficForwardingType -eq 'private' }
$testPolicyId = $policies[0].Id
Get-MgBetaNetworkAccessForwardingPolicyRule -ForwardingPolicyId $testPolicyId
SDK Version
2.29.0
Latest version known to work for scenario above?
No response
Known Workarounds
No response
Debug output
DEBUG: [CmdletBeginProcessing]: - Get-MgBetaNetworkAccessForwardingPolicyRule begin processing with parameterSet 'List'.
DEBUG: [Authentication]: - AuthType: 'Delegated', TokenCredentialType: 'InteractiveBrowser', ContextScope: 'CurrentUser', AppName: 'Microsoft Graph Command Line Tools'.
DEBUG: [Authentication]: - Scopes: [AccessReview.Read.All, Application.Read.All, AuditLog.Read.All, Calendars.Read, Calendars.Read.Shared, Channel.ReadBasic.All, ConsentRequest.Read.All, DelegatedPermissionGrant.Read.All, Device.ReadWrite.All, DeviceManagementConfiguration.Read.All, DeviceManagementManagedDevices.PrivilegedOperations.All, DeviceManagementManagedDevices.ReadWrite.All, DeviceManagementServiceConfig.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All, Domain.ReadWrite.All, email, Group.Read.All, Group.ReadWrite.All, GroupMember.Read.All, GroupMember.ReadWrite.All, IdentityRiskyUser.ReadWrite.All, Mail.Read, NetworkAccess.Read.All, openid, profile, Team.ReadBasic.All, User.Read, User.Read.All, UserAuthenticationMethod.Read.All, UserAuthenticationMethod.ReadWrite.All].
DEBUG: ============================ HTTP REQUEST ============================
HTTP Method:
GET
Absolute Uri:
https://graph.microsoft.com/beta/networkAccess/forwardingPolicies/88de4bbf-27fc-46b8-b926-87f7e4e896b7/policyRules
Headers:
FeatureFlag : 00000003
Cache-Control : no-store, no-cache
User-Agent : Mozilla/5.0,(Windows NT 10.0; Microsoft Windows 10.0.26200; en-US),PowerShell/2025.2.0
SdkVersion : graph-powershell-beta/2.29.0
client-request-id : 99b91890-3907-4b0f-ac87-9a80f4711f25
Accept-Encoding : gzip,deflate,br
Body:
DEBUG: ============================ HTTP RESPONSE ============================
Status Code:
OK
Headers:
Date : Thu, 10 Jul 2025 05:08:21 GMT
Transfer-Encoding : chunked
Connection : keep-alive
Vary : Accept-Encoding
Strict-Transport-Security : max-age=31536000
request-id : 972d1873-7839-4cfd-940d-b77f366ffd03
client-request-id : 99b91890-3907-4b0f-ac87-9a80f4711f25
x-ms-ags-diagnostic : {"ServerInfo":{"DataCenter":"West US 2","Slice":"E","Ring":"4","ScaleUnit":"005","RoleInstance":"MWH0EPF0009A7D2"}}
OData-Version : 4.0
X-Cache : CONFIG_NOCACHE
Body:
{
"@odata.context": "https://graph.microsoft.com/beta/$metadata#networkAccess/forwardingPolicies('88de4bbf-27fc-46b8-b926-87f7e4e896b7')/policyRules",
"value": []
}
DEBUG: [CmdletEndProcessing]: - Get-MgBetaNetworkAccessForwardingPolicyRule end processing.
Configuration
- OS: Windows 11 25H2 (OS Build 26200.5670)
- x64
- Powershell 7.5.2 and 5.1
Other information
Get-MgBetaNetworkAccessForwardingPolicy -Filter "TrafficForwardingType eq 'private'" | fl
Also reflects blank PolicyRules:
Description : This policy represents application segment configuration on appId
ed26595d-2982-4862-99da-342c53a26a5e
Id : a56c642a-4811-4dda-a4ee-265866c048b8
Name : Private Access Policy for App ed26595d-2982-4862-99da-342c53a26a5e
PolicyRules :
TrafficForwardingType : private
Version : 1.0.0
AdditionalProperties : {}
- Lenguaje dominante
- C#
- Estrellas
- 902
- Forks
- 233
- Merge medio
- 1 d 3 h
- PR fusionados (30 d)
- 24
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de microsoftgraph/msgraph-sdk-powershell
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
microsoftgraph/msgraph-sdk-powershell#3752 ·
Los mantenedores suelen responder en 1 día
-
New-MgGroupMember Missing from DocsPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertostatus:waiting-for-triage type:bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
microsoftgraph/msgraph-sdk-powershell#3751 ·
Los mantenedores suelen responder en 1 día
-
Graph PowerShell 2.41.0: Connect-MgGraph fails loading System.Text.Json 10; downgrading to 2.40.0 resolvesPosiblemente ocupada @svrooij la tomó hace 1 día. AbiertoNeeds: Attention :wave: status:waiting-for-triage type:bug
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
microsoftgraph/msgraph-sdk-powershell#3810 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Supported way to get the tokenAbiertostatus:waiting-for-triage type:feature
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
microsoftgraph/msgraph-sdk-powershell#3806 · 2 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Microsoft.Graph.Authentication fails after removal and re-import in the same PowerShell sessionAbiertostatus:waiting-for-triage type:bug
Dificultad 4/5 3-5 días Aptitud para principiantes 25/100
microsoftgraph/msgraph-sdk-powershell#3805 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de microsoftgraph/msgraph-sdk-powershell
Issues similares
-
[Doc Gap] Document new --enable-public-network-access breaking change for azurebackup vault createAbiertocopilot documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
Los mantenedores suelen responder en 1 día
-
area-dashboard
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
0 - Backlog Bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
BrighterCommand/Brighter#4539 ·
Los mantenedores suelen responder en 1 día
-
area-networking
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
dotnet/aspnetcore#69671 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Ignored test: FileLocalDataSourceTests.retries_loading_filePosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertotest
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
NethermindEth/nethermind#14274 ·
Los mantenedores suelen responder en 1 día