Skip to content

Detect aad exclusions near misses - #2423

Open
JosephRWalter wants to merge 13 commits into
mainfrom
2326-detect-aad-exclusions-near-misses
Open

JosephRWalter wants to merge 13 commits into
mainfrom
2326-detect-aad-exclusions-near-misses

Conversation

@JosephRWalter

@JosephRWalter JosephRWalter commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

🗣 Description

Adds near miss exclusion detection where "near miss" scenarios are identified when missing exclusions in the configuration would allow the policy to pass.

Identified near misses are added to the HTML, JSON, and PowerShell output.

💭 Motivation and context

Closes #2326

🧪 Testing

Locally test each AAD policy with exclusions using SCuBACached. Confirm the output is correct in the HTML, JSON, and PowerShell output.

Confirm the Rego unit tests and functional tests are passing for each test tenant.

✅ Pre-approval checklist

  • This PR has an informative and human-readable title.
  • PR targets the correct parent branch (e.g., main or release-name) for merge.
  • Changes are limited to a single goal - eschew scope creep!
  • Changes are sized such that they do not touch excessive number of files.
  • All future TODOs are captured in issues, which are referenced in code comments.
  • These code changes follow the ScubaGear content style guide.
  • Related issues these changes resolve are linked preferably via closing keywords.
  • All relevant type-of-change labels added.
  • All relevant project fields are set.
  • All relevant repo and/or project documentation updated to reflect these changes.
  • Unit tests added/updated to cover PowerShell and Rego changes.
  • Functional tests added/updated to cover PowerShell and Rego changes.
  • All automated checks (e.g., linting, static analysis, unit/smoke tests) passed.

✅ Pre-merge checklist

  • PR passed smoke test check.

  • PR/feature branch passes functional tests for relevant products, if applicable.

  • Feature branch has been rebased against changes from parent branch, as needed.

    Use Update branch button below or use this reference to rebase from the command line.

  • Resolved all merge conflicts on branch.

  • Squash all commits into one PR level commit using the Squash and merge button.

✅ Post-merge checklist

  • Feature branch deleted after merge to clean up repository.
  • Close issues resolved by this PR if the closing keywords did not activate.
  • Verified that all checks pass on parent branch (e.g., main or release-name) after merge.

@JosephRWalter JosephRWalter self-assigned this Sep 17, 2026
@JosephRWalter JosephRWalter added this to the Riptide milestone Sep 17, 2026
@atuomit
atuomit force-pushed the 2326-detect-aad-exclusions-near-misses branch from eb9fa8b to 6d43b78 Compare October 2, 2026 21:26
@sylvesterkaczmarek

Copy link
Copy Markdown

Rechecked current head c2200a9. The structured-output gap I raised is still present in CreateReport.psm1: the omitted and incorrect-result fragment objects include NearMisses, but the normal result object at the typical branch still omits the field.

So an ordinary failed AAD control can still show the near miss in human-readable details while losing the structured NearMisses data in the consolidated JSON. Please add NearMisses to the normal fragment and cover a normal Fail case in the JSON/output regression.

@atuomit
atuomit force-pushed the 2326-detect-aad-exclusions-near-misses branch from c2200a9 to 496ae9e Compare October 5, 2026 14:45
@atuomit
atuomit deployed to Development October 5, 2026 17:09 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active
@atuomit
atuomit deployed to Development October 5, 2026 17:16 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
Development — 4a9fd470 Deployed Oct 5, 2026 by atuomit via Test Security Suite / Sec_Tenant1_G5 #1466
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement This issue or pull request will add new or improve existing functionality ScubaGear 2.0 This issue is designated for version 2.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Detect AAD policies that would pass with configured exclusions

6 participants