microsoftgraph / microsoftgraph/msgraph-beta-sdk-python

sign_ins.get does not support the filter properties from Docs

Open
#828 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

status:waiting-for-triage type:bug
Dominant language
Python
Stars
44
Forks
16
Avg merge
20h 39m
Merged PRs (30d)
3

Description

Describe the bug

When attempting to get nonInteractiveUser and servicePrincipal sign-ins, we receive one the following error messages when we try to use the filter properties defined in the Official MSgraph Beta API documentation.

"Invalid filter clause: Could not find a property named 'servicePrincipalId' on type 'microsoft.graph.signIn'."

Invalid filter clause: Could not find a property named 'signInEventTypes' on type 'microsoft.graph.signIn'.", target=None)

Here are some example filters we have tried

filter_query = f"createdDateTime ge {start_time_str} and createdDateTime le {end_time_str} and signInEventTypes/any(t: t eq 'nonInteractiveUser' or t eq 'servicePrincipal')"

filter_query = "signInEventTypes/any(t: t eq 'nonInteractiveUser' or t eq 'servicePrincipal')"

filter_query = f"servicePrincipalId eq '{id}'"

Notes:

  1. This exact same code works fine via the Python Beta SDK if we only include the createdDateTime properties in the filter
  2. This exact same filter (including signInEventTypes/any property) works fine when used via the MSGraph Beta API over HTTP

Questions

  1. I understand this is a beta, but should we expect the Python SDK to behave differently from the Beta Docs and the Beta HTTP API?
Expected behavior
  1. The python beta SDK would support the same filter properties as documented in the MSGraph Beta API documentation
  2. The python beta SDK would support the same filter properties as the MSGraph Beta HTTP API
How to reproduce
import asyncio
import os

from azure.identity import InteractiveBrowserCredential
from kiota_abstractions.base_request_configuration import RequestConfiguration
from msgraph_beta import GraphServiceClient
from msgraph_beta.generated.audit_logs.sign_ins.sign_ins_request_builder import (
    SignInsRequestBuilder,
)

AZURE_TENANT_ID = os.environ.get("AZURE_TENANT_ID")
CERT = os.environ.get("CERT_PATH")


async def get_sign_ins(client):
    """Get sign-ins with SDK"""

    filter_query = (
        "signInEventTypes/any(t: t eq 'nonInteractiveUser' or t eq 'servicePrincipal')"
    )

    query_params = SignInsRequestBuilder.SignInsRequestBuilderGetQueryParameters(
        filter=filter_query,
        top=1,
    )

    request_configuration = RequestConfiguration(
        query_parameters=query_params,
    )
    result = await client.audit_logs.sign_ins.get(
        request_configuration=request_configuration
    )

    return result.value


async def main():
    """Main async function to process sign-ins"""

    credential = InteractiveBrowserCredential(
        tenant_id=AZURE_TENANT_ID, connection_verify=CERT
    )
    client = GraphServiceClient(
        credential,
        scopes=["https://graph.microsoft.com/.default"],
    )
    result = await get_sign_ins(client)
    print(result)


if __name__ == "__main__":
    asyncio.run(main())

SDK Version

1.31.0

Latest version known to work for scenario above?

No response

Known Workarounds

Use HTTP to hit beta API via python requests library

Debug output

"Invalid filter clause: Could not find a property named 'signInEventTypes' on type 'microsoft.graph.signIn'."

Configuration
  • OS: macOS Sequoia 15.3.1
  • Architecture: M1 ARM
Other information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the generated audit_logs/sign_ins/sign_ins_request_builder.py entry point used by SignInsRequestBuilder and inspect how the get request builds its filter query. Compare the SDK request with the documented beta HTTP request using the reproduction filters. Done means signInEventTypes and servicePrincipalId filters are accepted through the Python SDK.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
api
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.