redhat-cop / redhat-cop/group-sync-operator

Permission guidence for Azure AAD needed by the operator

Open
#272 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
Go
Stars
132
Forks
71
PR merge metrics
No merged PRs in 30d

Description

Currently, the recommendations for API permissions to be granted for Azure Active Directory is the following:

  • Group.Read.All
  • GroupMember.Read.All
  • User.Read.All

Alternately, the following permission can be used instead:

  • Directory.Read.All

Should the guidance be changed to use this new permission model or retain the existing guidance

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No file or test is named. Review the operator's existing Azure Active Directory permission guidance and the two permission alternatives in the issue, then establish which model the project should recommend; done means the guidance states the approved permissions and rationale clearly.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
authorization, cloud, documentation
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.