microsoftgraph / microsoftgraph/msgraph-metadata

Please consider open sourcing the authorization system

Open
#595 1 comment 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

ToTriage
Dominant language
XSLT
Stars
166
Forks
55
Avg merge
16h 12m
Merged PRs (30d)
14

Description

Thank you for building MS Graph. I appreciate the hard work and wisdom that goes into architecting, building, and maintaining this system.

Please consider making the authorization system open source. Today, administrators and security professionals mostly rely on documentation to understand, for example, which application roles are required to access endpoints. For example, the List users page states that one of the following application roles is required to access that endpoint:

User.Read.All, User.ReadWrite.All, Directory.Read.All, Directory.ReadWrite.All

The documentation for Directory.ReadWrite.All states:

Directory.ReadWrite.All grants access that is broadly equivalent to a global tenant admin.

However, I have performed and documented testing that leads me to believe this isn't actually true.

I believe this becomes a material security issue when admins and security professionals put undue attention on application roles that are not as powerful as others. For example, RoleManagement.ReadWrite.Directory allows the calling principal to promote itself or any other principal to Global Administrator. The documentation for that role states that:

Permissions that allow granting authorization, such as RoleManagement.ReadWrite.Directory, allow an application to grant additional privileges to itself, other applications, or any user. Use caution when granting any of these permissions.

But this application role does not come with the (I believed, warranted) warning about global admin equivalency the way Directory.ReadWrite.All does. The same issue exists for AppRoleAssignment.ReadWrite.Directory.

If you are able to open source the authorization system for MS Graph, I believe admins will be able to make much more well-informed decisions about the application roles they grant to service principals, and I believe security professionals will be able to much more efficiently audit those permissions to identify possible misconfigurations.

Thank you for taking the time to read my comment and thank you again for designing, building, and maintaining this system.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked List users permissions page, the Directory.ReadWrite.All permissions reference, and the documented testing results. The issue names no repository files, tests, or entry points; the scope and completion criteria for open-sourcing the authorization system would need to be defined first.

Written by the indexing model from the issue text.

Assessment

Domain
authorization, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.