I am building a dashboard to manage Office 365 resources but I instead of using a high-priviledge service account I would like that all tasks are running in the user context.
However the accounts used have MFA enabled and I am not sure how to integrate it.
Is there a way to run e.g."Connect-AdzureAd and authenticate with a MFA enabled account?
I don’t need to use the account logged in to Powershell Universal. It would be perfectly fine to have a button “Connect to Azure” that is displaying the Microsoft sign in page in a separate Window/Modal etc.
Something like this should be possible with OIDC. The idea is that you can specify the SaveTokens and Resource settings in appsettings.json and it will persist a token that can then be used with the O365 cmdlets. The user would then use the standard OIDC login flow including their MFA prompt. Then you could use that token during your O365 calls for that user’s session and everything would execute under their privileges.
I don’t have a good tutorial for this at the moment but will put it on my TODO to put something together.
This will require a code change in PSU. Luckily, it’s already been merged and we need to do a release for a critical issue we just discovered in 1.5.11.
I’ll write up a formal tutorial for the blog but this is how you’ll do it. You need to enable permissions to O365 (or whatever resource you are trying to access) for your application in the app registration.
Finally, you need to set the resource and response type appropriately in your appsettings.json for PSU. You also need to set SaveTokens to true. The resource URL is listed when you enable permissions in the Azure AD app registration. So depending on the resource, it will be a different URL.
This should work for O365, Graph and Azure management. I suspect 1.5.12 will go out today because the issue we just found is causing manually scheduled jobs to run 10x due to them failing and the service retrying the job…