Detect aad exclusions near misses - #2423
Open
JosephRWalter wants to merge 13 commits into
Open
JosephRWalter wants to merge 13 commits into
JosephRWalter wants to merge 13 commits into
Conversation
JosephRWalter
had a problem deploying
to
Development
September 17, 2026 16:39 — with
GitHub Actions
Failure
atuomit
force-pushed
the
2326-detect-aad-exclusions-near-misses
branch
from
October 2, 2026 21:26
eb9fa8b to
6d43b78
Compare
|
Rechecked current head c2200a9. The structured-output gap I raised is still present in CreateReport.psm1: the omitted and incorrect-result fragment objects include NearMisses, but the normal result object at the typical branch still omits the field. So an ordinary failed AAD control can still show the near miss in human-readable details while losing the structured NearMisses data in the consolidated JSON. Please add NearMisses to the normal fragment and cover a normal Fail case in the JSON/output regression. |
atuomit
force-pushed
the
2326-detect-aad-exclusions-near-misses
branch
from
October 5, 2026 14:45
c2200a9 to
496ae9e
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🗣 Description
Adds near miss exclusion detection where "near miss" scenarios are identified when missing exclusions in the configuration would allow the policy to pass.
Identified near misses are added to the HTML, JSON, and PowerShell output.
💭 Motivation and context
Closes #2326
🧪 Testing
Locally test each AAD policy with exclusions using SCuBACached. Confirm the output is correct in the HTML, JSON, and PowerShell output.
Confirm the Rego unit tests and functional tests are passing for each test tenant.
✅ Pre-approval checklist
✅ Pre-merge checklist
PR passed smoke test check.
PR/feature branch passes functional tests for relevant products, if applicable.
Feature branch has been rebased against changes from parent branch, as needed.
Use
Update branchbutton below or use this reference to rebase from the command line.Resolved all merge conflicts on branch.
Squash all commits into one PR level commit using the
Squash and mergebutton.✅ Post-merge checklist