AlexFilipin / ConditionalAccess

MIT License
274 stars 72 forks source link

Logic to protect inclusion and exclusion groups #14

Open AlexFilipin opened 4 years ago

AlexFilipin commented 4 years ago

We might want to protect exclusion groups (at least some) with the "Azure AD roles can be assigned to the group" flag that will protect it from other admin roles.

Thinking about: Sync account group, Emergency access account group and admin CA policies maybe even PERM exclusion groups of other policies.

AlexFilipin commented 4 years ago

microsoft.directory/groups/members/update

microsoft.directory/groups/allProperties/allTasks

microsoft.directory/groups.unified/members/update

microsoft.directory/groups.security/members/update

microsoft.directory/groups.assignableToRoles/allProperties/update

AlexFilipin commented 3 years ago

Waiting for additional AAD features, the number of assignableToRoles groups is limited so I dont think its a good path to take.