Create Pull Request
| Date | Scan | Status | Result |
|---|---|---|---|
| 2026-01-12 00:00 | #99 | completed |
Biased
|
| 2026-01-11 06:20 | #98 | completed |
Clean
|
| 2026-01-11 00:00 | #95 | cancelled |
Clean
|
| 2026-01-10 00:00 | #92 | completed |
Biased
|
| 2026-01-09 00:00 | #87 | cancelled |
Biased
|
| 2026-01-06 22:28 | #78 | completed |
Clean
|
| 2025-12-29 18:00 | #48 | cancelled |
Biased
|
| 2025-12-22 00:00 | #24 | cancelled |
Clean
|
| 2025-12-15 00:00 | #7 | completed |
Clean
|
| 2025-12-14 05:05 | #6 | completed |
Clean
|
# Install the module.
# Install-Module Microsoft.Graph -Scope CurrentUser
# The tenant ID
$TenantId = "aaaabbbb-0000-cccc-1111-dddd2222eeee"
# The name of your web app, which has a managed identity.
$webAppName = "SecureWebApp-20201106120003"
$resourceGroupName = "SecureWebApp-20201106120003ResourceGroup"
# The name of the app role that the managed identity should be assigned to.
$appRoleName = "User.Read.All"
# Get the web app's managed identity's object ID.
Connect-AzAccount -Tenant $TenantId
$managedIdentityObjectId = (Get-AzWebApp -ResourceGroupName $resourceGroupName -Name $webAppName).identity.principalid
Connect-MgGraph -TenantId $TenantId -Scopes 'Application.Read.All','AppRoleAssignment.ReadWrite.All'
# Get Microsoft Graph app's service principal and app role.
$serverApplicationName = "Microsoft Graph"
$serverServicePrincipal = (Get-MgServicePrincipal -Filter "DisplayName eq '$serverApplicationName'")
$serverServicePrincipalObjectId = $serverServicePrincipal.Id
$appRoleId = ($serverServicePrincipal.AppRoles | Where-Object {$_.Value -eq $appRoleName }).Id
# Assign the managed identity access to the app role.
New-MgServicePrincipalAppRoleAssignment `
-ServicePrincipalId $managedIdentityObjectId `
-PrincipalId $managedIdentityObjectId `
-ResourceId $serverServicePrincipalObjectId `
-AppRoleId $appRoleId