Securing SharePoint access with Managed Identities and Sites.Selected permission
In this post we will see how to secure your SharePoint authentication through PowerShell and Azure Automation with a managed identity and Sites.Selected permission in order to download or upload files.
The solution
1. Use Azure Automation account
2. Configure it with system managed identity
3. Add Sites.Selected SP permission
4. Give access to a specific site
5. Add a Runbook (script)
Sources to download
Click on the below GitHub picture to get following files:
- Assign_permissions.ps1
- Upload.ps1
- Download.ps1
Creating automation account
Purpose: here we will create the automation account with managed identity.
The managed identity is used to authenticate to your tenant, this way you don't need to provide credentials.
When you configure the managed identity, a new Azure Enterprise application will be created.
This one will be used to authenticate to our tenant and do API calls.
1. Go to Azure
2. Go to Automation accounts
3. Click on Create
4. Type an Automation name
5. Choose a Subscription, resource group and region
6. Go to Advanced tab
7. Select System assigned
8. Click on Review+Create
Adding permissions
So far, we have created the automation account
After creating the automation account with managed identity, we have now to give access to a SharePoint site.
Here we don't want to access to all SharePoint sites but only a specific one.
For that we need to add the Sites.Selected permission with Microsoft Graph.
Given that it's a managed identity we can not add permission through the Azure portal.
We need to use PowerShell for that.
Use Assign_permission.ps1 for this part.
The next step is to identity on on which SharePoint site the MI should have access.
Getting SharePoint site id
In order to upload/download something we need to identify the SharePoint site that will be used.
For this we need the SharePoint site path and ID.
To get the ID of a SharePoint site proceed as below:
1. Open your browser
2. Type the following URL:
https://yoursharepoint.sharepoint.com/sites/yoursite/_api/site/id
In my case it's:
https://systanddeploy.sharepoint.com/sites/Support/_api/site/id
Now to add the permission on the SharePoint site, proceed as below:
1. Open Graph Explorer here
2. Choose method POST
3. In url type the below one and replace sharepointsiteid with your SharePoint site id
https://graph.microsoft.com/v1.0/sites/sharepointsiteid/permissions
4. Go to Request body
5. Type the below body by replacing specified fields
6. Click on Run query
7. If you have an error 403 forbidden in Graph Explorer, click on Modify permissions
8. There you will find a permission to allow, so allow it
9. Click again on Run query
Authenticate to SharePoint
To authenticate to a the SharePoint site we use the below cmdline:
Connect-MgGraph -Identity
Upload file
The script to use for that is Upload.ps1 and is available here.
Download file
The script to use for that is Download.ps1 and is available here.
Enregistrer un commentaire