Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/tools4everbv/helloid-task-sa-target-azureactivedirectory-grouprevokeownership

Azure Active Directory - Group revoke ownership
https://github.com/tools4everbv/helloid-task-sa-target-azureactivedirectory-grouprevokeownership

azure-active-directory delegated-form powershell product service-automation task

Last synced: 12 days ago
JSON representation

Azure Active Directory - Group revoke ownership

Awesome Lists containing this project

README

        

# HelloID-Task-SA-Target-AzureActiveDirectory-GroupRevokeOwnership

## Prerequisites

Before using this snippet, verify you've met with the following requirements:

- [ ] AzureAD app registration
- [ ] The correct app permissions for the app registration
- [ ] User defined variables: `AADTenantID`, `AADAppID` and `AADAppSecret` created in your HelloID portal.
- [ ] Please see our documentation on how to create custom variables: (https://docs.helloid.com/en/variables/custom-variables.html)

## Description

This code snippet executes the following tasks:

1. Define a hash table `$formObject`. The keys of the hash table represent the properties to remove an owner from the group, while the values represent the values entered in the form.

> To view an example of the form output, please refer to the JSON code pasted below.

```json
{
"GroupIdentity": "9fd88320-368d-4613-b294-0d1c0f4653b9",
"OwnersToAdd": [
{
"UserId": "userId1",
"userPrincipleName": "[email protected]"

},
{
"UserId": "userId2",
"userPrincipleName": "[email protected]"
}
]
}
```

> :exclamation: It is important to note that the names of your form fields might differ. Ensure that the `$formObject` hashtable is appropriately adjusted to match your form fields.
> [See the Microsoft Docs page](https://learn.microsoft.com/en-us/graph/api/group-delete-owners?view=graph-rest-1.0&tabs=http)

2. Receive a bearer token by making a POST request to: `https://login.microsoftonline.com/$AADTenantID/oauth2/token`, where `$AADTenantID` is the ID of your Azure Active Directory tenant.

3. remove the Owners of a group using the: `Invoke-RestMethod` cmdlet. The hash table called: `$formObject` is passed to the body of the: `Invoke-RestMethod` cmdlet as a JSON object.