Loading...

Securing SharePoint access with Managed Identities and Sites.Selected permission

Reply A+ A-


In this post we will see how to secure your SharePoint authentication through PowerShell and Azure Automation with a managed identity and Sites.Selected permission in order to download or upload files.


The solution

1. Use Azure Automation account 

2. Configure it with system managed identity

3. Add Sites.Selected SP permission

4. Give access to a specific site

5. Add a Runbook (script)


Sources to download

Click on the below GitHub picture to get following files:

- Assign_permissions.ps1

- Upload.ps1

- Download.ps1



Creating automation account

Purpose: here we will create the automation account with managed identity.

The managed identity is used to authenticate to your tenant, this way you don't need to provide credentials.

When you configure the managed identity, a new Azure Enterprise application will be created.

This one will be used to authenticate to our tenant and do API calls.

1. Go to Azure

2. Go to Automation accounts

3. Click on Create

4. Type an Automation name

5. Choose a Subscription, resource group and region

6. Go to Advanced tab

7. Select System assigned


8. Click on Review+Create


Adding permissions

So far, we have created the automation account

After creating the automation account with managed identity, we have now to give access to a SharePoint site.

Here we don't want to access to all SharePoint sites but only a specific one.

For that we need to add the Sites.Selected permission with Microsoft Graph.


Given that it's a managed identity we can not add permission through the Azure portal.

We need to use PowerShell for that.

Use Assign_permission.ps1 for this part.

The next step is to identity on on which SharePoint site the MI should have access.


Getting SharePoint site id

In order to upload/download something we need to identify the SharePoint site that will be used. 

For this we need the SharePoint site path and ID.


To get the ID of a SharePoint site proceed as below:

1. Open your browser

2. Type the following URL: 

https://yoursharepoint.sharepoint.com/sites/yoursite/_api/site/id


In my case it's:

https://systanddeploy.sharepoint.com/sites/Support/_api/site/id


Now to add the permission on the SharePoint site, proceed as below:

1. Open Graph Explorer here 

2. Choose method POST


3. In url type the below one and replace sharepointsiteid with your SharePoint site id

https://graph.microsoft.com/v1.0/sites/sharepointsiteid/permissions

4. Go to Request body


5. Type the below body by replacing specified fields

6. Click on Run query


7. If you have an error 403 forbidden in Graph Explorer, click on Modify permissions

8. There you will find a permission to allow, so allow it

9. Click again on Run query


Authenticate to SharePoint

To authenticate to a the SharePoint site we use the below cmdline:

Connect-MgGraph -Identity 


Upload file

The script to use for that is Upload.ps1 and is available here.


Download file

The script to use for that is Download.ps1 and is available here.

slider 982542525659522747

Enregistrer un commentaire

Accueil item

Award

Sponsors

Learn KQL in one month

You want to support me ?

Mes articles en français

Books in French


Stats