Intune-Scripts icon indicating copy to clipboard operation
Intune-Scripts copied to clipboard

Additional checks for Get-AllAadGroupAssignments.ps1

Open Arne-RFA opened this issue 2 years ago • 4 comments

It would be great to see Conditional Access, App Protection, and App Configuration added.

Arne-RFA avatar Feb 24 '23 11:02 Arne-RFA

Okay let me work in this

JayRHa avatar Feb 24 '23 12:02 JayRHa

Any chance you could add Proactive Remediation, or any of the "Endpoint security" policies - antivirus, disk encryption, firewall, ASR, Endpoint detection and response?

kh-ps-dreamer avatar Mar 15 '23 21:03 kh-ps-dreamer

I would like to second the addition of Endpoint Security policies. Also, @JayRHa are you aware if this functionality will ever be implemented by Microsoft? I feel it is such an essential tool to keep track of where groups have been used. I'm so glad you have made this tool but I feel Microsoft should implement it themselves.

MStormW avatar Feb 29 '24 14:02 MStormW

I am adding to this thread with my findings, let me know if I should raise a new issue. It seems that the 'Security baselines' section (that looks at /intents) includes 'Microsoft Defender for Endpoint Security Baseline' baselines, but it does not include 'Security Baseline for Windows 10 and later' or 'Security Baseline for Microsoft Edge' baselines. I currently don't have a baseline under 'Windows 365 Security Baseline' or 'Microsoft 365 Apps for Enterprise Security Baseline' to determine if these are included or not, but I would guess not. I did use Graph Explorer to look around, and found that they are included in /configurationPolicies, but this includes other policies as well. For now I've changed my local copy and added this as a topic.

ivassallo19 avatar Jul 04 '24 00:07 ivassallo19