Skip to content

Microsoft Connector: Update group scope to groupMember.read.all #4046

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

ap0phi5
Copy link

@ap0phi5 ap0phi5 commented Mar 13, 2025

Overview

This is a small change to reduce the default permission scope for a Microsoft connector from the overly-permissive directory.read.all down to groupMember.read.all.

What this PR does / why we need it

Closes #3989

@ap0phi5 ap0phi5 changed the title Update group scope to groupMember.read.all Microsoft Connector: Update group scope to groupMember.read.all Mar 13, 2025
@ap0phi5 ap0phi5 marked this pull request as ready for review March 13, 2025 14:29
@ap0phi5
Copy link
Author

ap0phi5 commented Mar 15, 2025

Anyone able to allow this to run the CI tests?

@ap0phi5
Copy link
Author

ap0phi5 commented Mar 24, 2025

@nabokihms If it is within your purview, could you let the tests run on this please?
The details look a bit old but I'm assuming this tenant is still available?
https://github.com/dexidp/dex/blob/master/connector/microsoft/microsoft_test.go#L20-L23

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Microsoft Connector: Overly-permissive scope
1 participant