Identity Governance with Microsoft Graph results in 403 Unknown Error (PIM)

Viewed 458

There is a feature in Azure which is called Identity Governance or Entitlement Management. This feature allows to create access packages and manage user permissions with a request-approve workflow.

I want to automate the creation of the AccessPackages and AccessPackageCatalog Resources. Azure CLI and the Azure PWSH Module do not support the AccessPackages. The only way to automate this is described here: https://github.com/MicrosoftDocs/azure-docs/issues/52179 which states: "Use the Microsoft Graph beta API"

I tried the following to access the API from the commandline:

Using plain powershell:

      $tokenJson=$(az account get-access-token --resource-type ms-graph)
      $tokenObject=$(echo $tokenJson | ConvertFrom-Json)
      $headers = @{Authorization = "Bearer $($tokenObject.accessToken)"}
      $result = Invoke-WebRequest https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/accessPackages -Headers $headers

or using az rest

az rest --method get --uri https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/accessPackages

both request result in the following error with a 403 response:

{
  "error": {
    "code": "UnknownError",
    "message": "",
    "innerError": {
      "request-id": "0cd50759-d95a-4171-a942-3424cb19a622",
      "date": "2020-05-26T15:34:48"
    }
  }
}

When I try to view the AccessPackages inside the Portal everything works as expected: I can list and create the Packages.

SIDE NOTE I do NOT have permanent access to the Identity Governance pane in azure. Instead I must use Privileged Identity Management to Activate the User Administrator Role for my Account.

az logout && az login after Role activiation did not change anything.

0 Answers
Related