* Capture status code in GraphError
* Add comments to GraphError fields
* Parse auth errors returned by AzureTokenProvider
* Update tests to use NewClient
* Add logging to lib/msgraph.Client
* Add client-request-id header
* Fix typos in api/types.ValidateMSGraphEndpoints
* Ignore StatusCode field during unmarshalling
* Check for `authFailedError.RawResponse.Body != nil`
* Move credential verification from e/lib/intune to lib/msgraph
* Remove request logging
* set and validate default graph endpoint
* add IterateUsersTransitiveMemberOf method to list user groups
* run make fix-imports
* fix: return on group type error:
- updates test
* Initial command to create the managed identity and role
* Adding permissions and applying command params
* Adding graph permissions to the MSI
* Updating parameters
* Adding some details and cleaning up comments
* Fixing go.sum
* Linting
* License
* PR feedback
* Decoupling sync config with an interface for testing
* Tweaks to test mocking
* PR feedback
* Rebase adjustments
* PR feedback
* Switch to empty struct maps instead of bool maps for set representation
* Godocs
* Adding user agent to Azure SDK requests
* Linting
* Protobuf and configuration for Access Graph Azure Discovery
* Adding the Azure sync module functions along with new cloud client functionality
* Forgot to decouple role definitions fetching function from the fetcher
* Moving reconciliation to the upstream azure sync PR
* Moving reconciliation test to the upstream azure sync PR
* Updating go.sum
* Fixing rebase after protobuf gen
* Nolinting until upstream PRs
* Updating to use existing msgraph client
* Adding protection around nil values
* PR feedback
* Updating principal fetching to incorporate metadata from principal subtypes
* Updating opts to not leak URL parameters
* Conformant package name
* Using variadic options
* PR feedback
* Removing memberOf expansion
* Expanding memberships by calling memberOf on each user
* Also returning expanded principals for improved readability
* Removing ptrToList
* PR feedback
* Rebase go.sum stuff
* Go mod tidy
* Linting
* Linting
* Collecting errors from fetching memberships and using a WithContext error group
* Fixing go.mod
* Update lib/msgraph/paginated.go
Co-authored-by: Tiago Silva <tiago.silva@goteleport.com>
* PR feedback
* e ref update
* e ref update
* Fixing method
* Fetching group members from groups rather than memberships of each principal
* Linting
---------
Co-authored-by: Tiago Silva <tiago.silva@goteleport.com>
To populate the given name and surname traits, we must parse them from
Entra ID responses. This PR parses the given name and surname artifacts
from the json response.
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
Entra sometimes sends the OptionClaims when retrieving a certain application if only SAML2Token is set, other times it doesn't return them.
This PR fills all id and access token values so entra doesn't fail to send the optional token value.
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* [entraid] store entra `appId` in plugin settings
This PR stores the Entra ID appID of the application used for SSO in Entra ID plugin settings.
This field filled in a best effort scenario and might be empty for old Entra Plugins.
Newly created plugins will make the field mandatory.
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* handle code review comments
---------
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* [entraid] Expose Application `OptionalClaims` and Groups AD settings
This PR exposes Entra ID settings for `OptionalClaims` where applications store the info regarding how the group claim is mapped to SAML properties.
It also exposes the GroupID settings:
- `onPremisesDomainName`
- `onPremisesNetBiosName`
- `onPremisesSamAccountName`
That will be later used compute group claims with the Teleport SAML connector.
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* handle code review comments
---------
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
This PR fixes a typo where the error was incorrectly ignored and caused failures when group membership included other groups and any unsupported kinds.
This PR fixes that by properly returning `unsupportedGroupMember` while also supports parsing groups that are member of other groups.
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* [entraid] add setup script for offline clusters.
This PR adds a cli configuration for Entra ID where it's possible to default to system credentials instead of relying on OIDC for authentication in EntraID. OIDC is not always a possibility specially when the cluster is private and not internet acessible.
The UX is the following:
```text
Step 1: Run the Setup Script
1. Open **Azure Cloud Shell** (Bash) using **Google Chrome** or **Safari** for the best compatibility.
2. Upload the setup script using the **Upload** button in the Cloud Shell toolbar.
3. Once uploaded, execute the script by running the following command:
$ bash entraid.sh
**Important Considerations**:
- You must have **Azure privileged administrator permissions** to complete the integration.
- Ensure you're using the **Bash** environment in Cloud Shell.
- During the script execution, you'll be prompted to run 'az login' to authenticate with Azure. **Teleport** does not store or persist your credentials.
- **Mozilla Firefox** users may experience connectivity issues in Azure Cloud Shell; using Chrome or Safari is recommended.
Once the script completes, type 'continue' to proceed, 'exit' to quit: continue
Step 2: Input Tenant ID and Client ID
With the output of Step 1, please copy and paste the following information:
Enter the Tenant ID: 1056b571-0390-4b08-86c8-2edba8d9ae79
Enter the Client ID: 1056b571-0390-4b08-86c8-2edba8d9ae79
Successfully created EntraID plugin "name".
```
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
* move function to api
* handle code review comments
* Apply suggestions from code review
Co-authored-by: Marco Dinis <marco.dinis@goteleport.com>
* fix url
* enable group claims
* add godoc
* handle code review comments
* fix gomod
---------
Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
Co-authored-by: Marco Dinis <marco.dinis@goteleport.com>
* Add MS Graph client skeleton
* Complete retry logic
* Add GetID() to GroupMember
* Parse MS Graph API error responses
* Pull out page size into config
* Add missing "patch" methods to client interface
* Move code around
* Factor out roundtrip()
* Fill out remaining methods
* Add godocs and solve lints
* Run gci
* Move godocs to the interface
* Add missing method
* Finish errors_test
* close body in test
* nit
* Add license headers
* Move azureoidc onboarding code to msgraph.Client
* Make AzureTokenProvider public
* Use cmp.Or to shorten config defaults handling
* Address review nits
* Parallelize tests
* nit
* Respect context cancellation in retry logic
* Utilize BlockUntil in tests
* Remove Client interface, make client struct public
* Prefer defaults.HTTPClient to http.DefaultClient
* Iterate entra apps, do not buffer all in memory
* nit
* Set additional timeouts on default HTTP client
* Escape path segments when constructing URLs
* Add a general timeout for default HTTP client