-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
P1Priority 1 - HighPriority 1 - HighmoduleNew collector or tester moduleNew collector or tester module
Description
Summary
Add Microsoft Entra ID (Azure AD) modules for identity and access management evidence collection and active MFA testing.
Collector: azure.conditional_access
- Query Microsoft Graph API for Conditional Access policies
- Collect MFA requirements, device compliance policies, sign-in risk policies
- Map to IAM control family
- Produce
passive_observationevidence
Tester: azure.mfa_bypass
- Safety class:
safe(authentication attempt only) - Attempt sign-in without satisfying MFA via ROPC flow
- Verify Conditional Access policy blocks the attempt
- Full test transcript
Credentials
AZURE_TENANT_ID— Azure AD tenantAZURE_CLIENT_ID— App registration client IDAZURE_CLIENT_SECRET— App registration secret
Acceptance Criteria
-
ocean collect azure.conditional_accessreturns CA policy evidence -
ocean test azure.mfa_bypass --target productionruns safely - Tests with httptest mock of Graph API
- Handles pagination on Graph API responses
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
P1Priority 1 - HighPriority 1 - HighmoduleNew collector or tester moduleNew collector or tester module