There is a feature in Azure which is called Identity Governance or Entitlement Management. This feature allows to create access packages and manage user permissions with a request-approve workflow.
I want to automate the creation of the AccessPackages and AccessPackageCatalog Resources. Azure CLI and the Azure PWSH Module do not support the AccessPackages. The only way to automate this is described here: https://github.com/MicrosoftDocs/azure-docs/issues/52179 which states: "Use the Microsoft Graph beta API"
I tried the following to access the API from the commandline:
Using plain powershell:
$tokenJson=$(az account get-access-token --resource-type ms-graph)
$tokenObject=$(echo $tokenJson | ConvertFrom-Json)
$headers = @{Authorization = "Bearer $($tokenObject.accessToken)"}
$result = Invoke-WebRequest https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/accessPackages -Headers $headers
or using az rest
az rest --method get --uri https://graph.microsoft.com/beta/identityGovernance/entitlementManagement/accessPackages
both request result in the following error with a 403 response:
{
"error": {
"code": "UnknownError",
"message": "",
"innerError": {
"request-id": "0cd50759-d95a-4171-a942-3424cb19a622",
"date": "2020-05-26T15:34:48"
}
}
}
When I try to view the AccessPackages inside the Portal everything works as expected: I can list and create the Packages.
SIDE NOTE I do NOT have permanent access to the Identity Governance pane in azure. Instead I must use Privileged Identity Management to Activate the User Administrator Role for my Account.
az logout && az login after Role activiation did not change anything.