Add Defender permissions part of "a365 setup all" - #485
Slava Reznitsky (slreznit) wants to merge 8 commits into
Conversation
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
Updates the Defender API app role and delegated scope value from AIAgentsRTP.ToolInvocation to RealtimeProtection.Process, and renames the constant accordingly since the old name no longer described the role. NOT YET VERIFIED AGAINST A LIVE RESOURCE. The resource SP still publishes AIAgentsRTP.ToolInvocation in the agent365003 tenant, and the resource is not provisioned in the corp tenant at all, so the new value could not be confirmed anywhere. Until the Defender-side rename ships, the combined /v2.0/adminconsent URL will fail with AADSTS650053 for every resource in the request - Graph, MCP, Bot, Observability and Power Platform - not just Defender, and the S2S app role lookup will find no matching appRoles entry. Confirm the resource publishes the new value before merging. Adds DefenderApi_ScopeValue_MatchesValuePublishedOnResource pinning the literal string so future drift fails a test that explains the blast radius. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The S2S endpoint authorizes registered agents without OtelWrite whatever the auth mode, so s2s/both no longer request it either. They still grant any other app-role specs (e.g. Defender once #485 lands). Agents whose SDK still exports through the delegated route grant OtelWrite manually, as the CHANGELOG upgrade note describes. AI Teammate setup is unchanged. Tests encode the changed requirement for s2s/both (flag or config) and are mutation-checked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12
… default (#501) * Add --skip-observability-permissions to setup all Blueprint agents that export telemetry through the app-only S2S endpoint (microsoft/Agent365-nodejs#290, microsoft/Agent365-Samples#339) are authorized by their agent registration, so the Observability API OtelWrite permission, and the admin consent it needs, is unnecessary for them. - New opt-in `setup all --skip-observability-permissions` omits Observability API from the permission specs (inheritable permissions, app role grants, batch consent) and from the per-resource and combined admin consent URLs. Defaults are unchanged: the published SDKs still export to the non-S2S endpoint by default. - The flag fails fast for AI Teammate agents and with authMode s2s/both, since OtelWrite is the only app role those modes grant. A contradicting --authmode flag is rejected before bootstrap signs in. - With the flag, a failed agent registration is an error (exit 1), because registration is then the agent's only Observability authorization. - Fix: `setup all --agent-registration-only` exited 0 when registration failed. - Dry run plan, setup summary, CHANGELOG, and docs updated. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Make skipping Observability permissions the default for blueprint agents Per 3P Dev Scale scrum feedback, the no-consent flow becomes the main path instead of an opt-in flag. - Remove --skip-observability-permissions. Blueprint agents in the default (obo) auth mode no longer request Observability API permissions; registered agents export telemetry with an app-only token over the S2S endpoint. - authMode s2s/both keep requesting OtelWrite, the only app role those modes grant; `both` also covers agents whose SDK still exports through the delegated (OBO) route. - AI Teammate setup is unchanged until instance creation can be validated end to end. - Registration failure stays an error on the default path. - Tests: the default plan omits Observability; s2s/both (flag or config) keep it; AI Teammate keeps it. Mutation-checked. Validated live: a roleless app-only token for a registered agent identity exports 200 on S2S; an unregistered identity gets 403 insufficient_scope. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Stop requesting Observability permissions in every blueprint auth mode The S2S endpoint authorizes registered agents without OtelWrite whatever the auth mode, so s2s/both no longer request it either. They still grant any other app-role specs (e.g. Defender once #485 lands). Agents whose SDK still exports through the delegated route grant OtelWrite manually, as the CHANGELOG upgrade note describes. AI Teammate setup is unchanged. Tests encode the changed requirement for s2s/both (flag or config) and are mutation-checked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address #501 review: registration and consent edge cases - When registration is required (--agent-registration-only, or Observability permissions not requested), an inconclusive registration check now fails setup instead of passing. The stored ID is kept and no duplicate registration is created. The optional path still retains the stored ID. - When Observability is not included, drop an Observability consent entry saved by an earlier run so the admin is not asked for it. - Keep Observability for an AI Teammate config retained for a dry run (skip only for an effective blueprint selection). - Scope the guided-setup OtelWrite grant steps to AI Teammates and SDKs that still export through the delegated route; fix two stale doc comments. Regression tests cover each case and are mutation-checked. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Condense #501 changelog entries and refresh stale test wording Make the upgrade note one consumer-facing sentence, and update the Fixed entry: setup exits 1 when registration fails or cannot be verified for blueprint agents as well as with --agent-registration-only. Replace "without the flag" in a registration test, since the flag was removed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Scope the Observability upgrade note to delegated-route agents The upgrade note opened by saying every existing agent needs the Observability permissions, which contradicted the S2S exception. Scope the heading and requirement to agents that export through the delegated (OBO) route. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address #501 review: s2s/both summary and failed app-role hand-off - Setup summary: blueprint agents no longer request any app role (OtelWrite was the only one), so an s2s or both run has no S2S grant. The Blueprint Permission Grants row now says so instead of reporting a delegated grant, or a PENDING with no action item for non-admin s2s runs: "not required (no S2S app roles to grant)" for s2s, and the delegated status plus "no S2S app roles to grant" for both. - The S2S PowerShell hand-off lists the app roles that were actually not assigned, recorded per blueprint and agent identity, instead of hardcoding Observability OtelWrite. AI Teammates still get the OtelWrite step because they still request it. - A stale Observability consent URL is also cleared on admin runs, and only the URL is cleared: ConsentGranted and the inheritable-permission state are kept, since re-running setup does not revoke. - Document why registration is always required in real runs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Align #501 docs with the s2s/both summary - CHANGELOG upgrade note: the setup summary prints the OtelWrite PowerShell steps only for AI Teammates now, so point blueprint agents on the delegated route to Option A. - Setup README: s2s and both have no app role to assign for blueprint agents, and the summary reports the S2S grant as not required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * List a hand-off per failed S2S target in the setup summary When the blueprint and agent-identity app-role grants both fail in one run, the summary printed only the agent identity's roles and dropped the blueprint's. It now prints one hand-off per failed target, each listing that target's pending roles and principal. A single failed target prints as before. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Qualify the s2s/both README note and de-duplicate pending roles - README: s2s and both have nothing to assign for blueprint agents only when no other permission adds an app role. - Setup summary: a role recorded twice for the same target is listed once. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address observability S2S review feedback Align guided setup docs with the app-only S2S telemetry model, fail setup when a missing blueprint secret blocks required registration, and update dry-run/help/summary remediation for skipped OtelWrite. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Clarify delegated-route upgrade note Point new blueprint agents that still use the delegated Observability route to the custom permissions command that stamps inheritable permissions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Keep the setup admin removal note and fix the missing-secret retry advice - CHANGELOG upgrade note: keep stating that `a365 setup admin` was removed in this release, next to the new `setup permissions custom` route. - Missing blueprint secret: the error now says to re-run `a365 setup blueprint` and then `a365 setup all`. `--agent-registration-only` skips identity creation, so it can't recover a run that never created the agent identity. The test pins this. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Point the Observability opt-back-in command at the cloud's app ID After merging #478, sovereign clouds use their own Observability app IDs, so the README's opt-back-in command no longer hard-codes the commercial ID. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Address observability opt-back-in review Separate default Observability omission from effective requested permissions when custom Observability permissions are configured, and update dry-run/help/docs for cloud-aware S2S guidance. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Tighten observability opt-back-in handling Require custom Observability opt-back-in to target the configured cloud and OtelWrite, track identity and registration failure severity explicitly, and clarify delegated-route documentation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 * Record the auth mode before the agent identity step EffectiveAuthMode and NoS2SAppRolesToGrant were set only after an agent identity existed, so when identity creation failed an s2s/both run with no app roles to grant could be summarized as a pending or delegated grant instead of "no S2S app roles to grant". Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12 --------- Co-authored-by: Krishnadheeraj <12496535+DheerajPannala@users.noreply.github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 5cbf5f6b-cc40-4b7e-a591-65848db73a12
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This reverts commit 50cd7bd.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 1
| ("Power Platform API", PowerPlatformConstants.PowerPlatformApiResourceAppId, PowerPlatformConstants.PermissionNames.ConnectivityConnectionsRead, "Delegated"), | ||
| ]; | ||
| }; | ||
|
|
||
| if (defenderPermissionMode is DefenderPermissionMode.Application or DefenderPermissionMode.Both) | ||
| specs.Insert(2, ("Defender API", ConfigConstants.DefenderApiAppId, ConfigConstants.DefenderApiRealtimeProtectionScope, "Application")); |
| Agents provisioned before this release need `RealtimeProtection.Evaluate.All` granted as both a **delegated** and an **application** permission on the blueprint app for the Defender security integration. Requires Global Administrator. Follow the steps above, searching for `86a21212-634e-4553-b3d6-e477e4c9d9ec` in step 2 and selecting `RealtimeProtection.Evaluate.All` in steps 3 and 4. Re-running `a365 setup all` grants it automatically. | ||
|
|
||
| ### Added | ||
| - `RealtimeProtection.Evaluate.All` on the Defender API is now granted automatically during `a365 setup` as both a delegated and an application permission, enabling the Microsoft Defender security integration without manual Entra steps. |
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 2
Open (5)
FixedApiAppRoleHandoffSpecs hard-codes the commercial Observability API app id… · New FixedApiAppRoleHandoffSpecs hard-codes the commercial Observability app ID… The PR title/description specifically targetsa365 setup all, but the changelog entry says the… · New The Defender app id is duplicated here as a raw string while other entries already reference… · New The changelog is inconsistent about which command performs the automatic grant: line 33 says…
| [ | ||
| ("Observability API", ConfigConstants.ObservabilityApiAppId, ConfigConstants.ObservabilityApiOtelWriteScope), | ||
| ("Defender API", ConfigConstants.DefenderApiAppId, ConfigConstants.DefenderApiRealtimeProtectionScope), | ||
| ]; | ||
|
|
| Agents provisioned before this release need `RealtimeProtection.Evaluate.All` granted as both a **delegated** and an **application** permission on the blueprint app for the Defender security integration. Requires Global Administrator. Follow the steps above, searching for `86a21212-634e-4553-b3d6-e477e4c9d9ec` in step 2 and selecting `RealtimeProtection.Evaluate.All` in steps 3 and 4. Re-running `a365 setup all` grants it automatically. | ||
|
|
||
| ### Added | ||
| - `RealtimeProtection.Evaluate.All` on the Defender API is now granted automatically during `a365 setup` as both a delegated and an application permission, enabling the Microsoft Defender security integration without manual Entra steps. |
| "00000003-0000-0000-c000-000000000000", // Microsoft Graph | ||
| "5a807f24-c9de-44ee-a3a7-329e88a00ffc", // Agent 365 Messaging Bot API | ||
| "9b975845-388f-4429-889e-eab1ef63949c", // Agent 365 Observability API | ||
| "86a21212-634e-4553-b3d6-e477e4c9d9ec", // Agent 365 Defender API |


Summary
RealtimeProtection.Evaluate.Allpermission duringa365 setup allfor both delegated (OBO) and application (S2S) flows.api://86a21212-634e-4553-b3d6-e477e4c9d9ecin individual and combined admin-consent URLs.mainchanges while preserving cloud-aware Observability behavior.Testing
dotnet test src\tests.proj --configuration Release --no-restore