Bug in "Update-MgPolicyDefaultAppManagementPolicy"? - restrictionType "customPasswordAddition" and "symmetricKeyAddition" is null even if set?
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- powershell
- 領域
- api
調査の方向性
Update-MgPolicyDefaultAppManagementPolicy コマンドレットから始め、提供された PowerShell 5.1 および SDK 2.28.0 の例を使用して、その PATCH 要求を /policies/defaultAppManagementPolicy からの GET 応答と比較します。customPasswordAddition と symmetricKeyAddition が SDK または Graph API によって省略されているかを確認し、構成された 2 つの制限が期待どおりに返されることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Describe the bug
I feel this is so strange - no errors when parseing the content via cmdlet "Update-MgPolicyDefaultAppManagementPolicy" in PowerShell, and as I see it Entra ID Auditlog also shows it right...
And when I looking in docs at https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.identity.signins/update-mgpolicydefaultappmanagementpolicy?view=graph-powershell-1.0 it should work just fine....
Working on a small tool as I shared a teaser here: https://www.linkedin.com/feed/update/urn:li:activity:7337869500135919617/ aka "Entra ID Application Policy Manager" so this type of errors is a bit enoying as it breaks stuff for people there is useing Entra ID Application Management Policies...
Tested here with:
2.28.0 Microsoft.Graph.Applications
2.28.0 Microsoft.Graph.Authentication
2.28.0 Microsoft.Graph.Identity.SignIns
Will test other too soon and update here!
Expected behavior
I exprect the values set, it not returned at "null" if etc. set to P40D or so.
How to reproduce
- run this to parse it to Graph (will not show any errors):
$params = @{
isEnabled = $true
applicationRestrictions = @{
passwordCredentials = @(
@{
restrictionType = "passwordAddition"
maxLifetime = $null
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2021-01-01T10:37:00Z")
}
@{
restrictionType = "passwordLifetime"
maxLifetime = "P40D"
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2017-01-01T10:37:00Z")
}
@{
restrictionType = "symmetricKeyAddition"
maxLifetime = "P40D"
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2021-01-01T10:37:00Z")
}
@{
restrictionType = "customPasswordAddition"
maxLifetime = "P40D"
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2015-01-01T10:37:00Z")
}
@{
restrictionType = "symmetricKeyLifetime"
maxLifetime = "P40D"
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2015-01-01T10:37:00Z")
}
)
keyCredentials = @(
@{
restrictionType = "asymmetricKeyLifetime"
maxLifetime = "P30D"
restrictForAppsCreatedAfterDateTime = [System.DateTime]::Parse("2015-01-01T10:37:00Z")
}
)
}
}
Update-MgPolicyDefaultAppManagementPolicy -BodyParameter $params
- Check if the settings is set - both via Entra ID Audit log like here:
and via etc. https://developer.microsoft.com/en-us/graph/graph-explorer with a GET call to "https://graph.microsoft.com/v1.0/policies/defaultAppManagementPolicy" - here you will see this for the above code:
- Done - the policy is set in Entra ID - but the 2 parts customPasswordAddition and symmetricKeyAddition is not set - the rest are... This is tested for applicationRestrictions for now (will test more)
SDK Version
2.28.0
Latest version known to work for scenario above?
No response
Known Workarounds
No response
Debug output
Click to expand log
``` Update-MgPolicyDefaultAppManagementPolicy -BodyParameter $params -Verbose VERBOSE: Performing the operation "Update-MgPolicyDefaultAppManagementPolicy_Update" on target "Call remote 'PATCH /policies/defaultAppManagementPolicy' operation". ```Configuration
$PSVersionTable
Name Value
---- -----
PSVersion 5.1.26100.4061
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.26100.4061
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
Windows 11 26100.3983, x64
Other information
This bug is reported back in the channels I have too as a Microsoft MVP and as a member of the CCP Communities..
- 主要言語
- C#
- スター
- 902
- フォーク
- 233
- 平均マージ
- 1日 22時間
- マージ済み PR(30日)
- 29
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoftgraph/msgraph-sdk-powershell のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
microsoftgraph/msgraph-sdk-powershell#3752 ·
メンテナーはふだん 2 日以内に返信
-
status:waiting-for-triage type:bug
難易度 4/5 3〜5日 初心者へのやさしさ 22/100
microsoftgraph/msgraph-sdk-powershell#3822 ·
メンテナーはふだん 2 日以内に返信
-
Microsoft.Graph.Authentication dependency Microsoft.Graph.Authentication.Loader.dll is unsignedオープンstatus:waiting-for-triage type:bug
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
microsoftgraph/msgraph-sdk-powershell#3819 ·
メンテナーはふだん 2 日以内に返信
-
Connect-MgGraph on 2.41 crashes when making a connection with cert, fixes when using 2.39 or lowerオープンstatus:waiting-for-triage type:bug
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
microsoftgraph/msgraph-sdk-powershell#3816 ·
メンテナーはふだん 2 日以内に返信
-
status:waiting-for-triage type:feature
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
microsoftgraph/msgraph-sdk-powershell#3806 · コメント 3 件 · リアクション 3 件 ·
メンテナーはふだん 2 日以内に返信
microsoftgraph/msgraph-sdk-powershell の issue をすべて見る
似ている issue
-
[誤判定] `define` が `デフィね`・`デフィ値` になる対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン再現済み 要トリアージ 誤判定
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
yksr-melt/Meltype#421 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 64/100
Facepunch/sbox-public#12063 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
documentation
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
facioquo/stock-indicators-dotnet#2316 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
ionide/FsAutoComplete#1559 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
lostindark/DriverStoreExplorer#477 ·
メンテナーはふだん 1 日以内に返信