From bcfbdabb3a0595ba839238926436e80e384007c1 Mon Sep 17 00:00:00 2001 From: 0xDarknightHacks <171492723+0xDarknightHacks@users.noreply.github.com> Date: Sat, 26 Sep 2026 22:39:01 +0200 Subject: [PATCH] Reduce redundant Graph requests in Conditional Access collection --- ...t-MonkeyMSGraphConditionalAccessPolicy.ps1 | 30 ++++--------------- .../ConditionalAccessGraphRequests.Tests.ps1 | 24 +++++++++++++++ 2 files changed, 29 insertions(+), 25 deletions(-) create mode 100644 tests/unit/core/ConditionalAccessGraphRequests.Tests.ps1 diff --git a/src/monkey365/core/api/entraid/msgraph/helpers/policies/Get-MonkeyMSGraphConditionalAccessPolicy.ps1 b/src/monkey365/core/api/entraid/msgraph/helpers/policies/Get-MonkeyMSGraphConditionalAccessPolicy.ps1 index 14209e59..7bec89c0 100644 --- a/src/monkey365/core/api/entraid/msgraph/helpers/policies/Get-MonkeyMSGraphConditionalAccessPolicy.ps1 +++ b/src/monkey365/core/api/entraid/msgraph/helpers/policies/Get-MonkeyMSGraphConditionalAccessPolicy.ps1 @@ -86,31 +86,11 @@ Function Get-MonkeyMSGraphConditionalAccessPolicy{ Debug = $O365Object.debug; } $caps_ = Get-MonkeyMSGraphObject @params - #Check if detailed cap - if($PSBoundParameters.ContainsKey('detailed') -and $PSBoundParameters.detailed){ - $cap_ = New-Object System.Collections.Generic.List[System.Object] - foreach($cap in $caps_){ - $objectType = ('identity/conditionalAccess/policies/{0}' -f $cap.id) - $params = @{ - Authentication = $graphAuth; - ObjectType = $objectType; - Environment = $Environment; - ContentType = 'application/json'; - Method = "GET"; - APIVersion = $APIVersion; - InformationAction = $O365Object.InformationAction; - Verbose = $O365Object.verbose; - Debug = $O365Object.debug; - } - $cap = Get-MonkeyMSGraphObject @params - if($cap){ - #Add to array - [void]$cap_.Add($cap); - } - Start-Sleep -Milliseconds 1000 - } - $caps_ = $cap_ - } + # The collection endpoint already returns the ConditionalAccessPolicy resources + # consumed by Monkey365 (conditions, grantControls and sessionControls included). + # Keep -Detailed for backward compatibility, but do not fan out into one GET per + # policy. Conditional Access is tightly throttled and batching those point GETs + # reduces envelopes rather than reducing Graph work. } if($null -ne $caps_){ return $caps_ diff --git a/tests/unit/core/ConditionalAccessGraphRequests.Tests.ps1 b/tests/unit/core/ConditionalAccessGraphRequests.Tests.ps1 new file mode 100644 index 00000000..6de774c5 --- /dev/null +++ b/tests/unit/core/ConditionalAccessGraphRequests.Tests.ps1 @@ -0,0 +1,24 @@ +Set-StrictMode -Version Latest + +Describe 'Conditional Access Graph request behavior' { + BeforeAll { + $repoRoot = (Resolve-Path (Join-Path $PSScriptRoot '../../..')).Path + $sourcePath = Join-Path $repoRoot 'src/monkey365/core/api/entraid/msgraph/helpers/policies/Get-MonkeyMSGraphConditionalAccessPolicy.ps1' + $source = Get-Content -LiteralPath $sourcePath -Raw + } + + It 'preserves the Detailed compatibility parameter' { + $source | Should -Match '\[Switch\]\$detailed' + } + + It 'preserves collection and direct policy lookup endpoints' { + $source | Should -Match '\$objectType\s*=\s*''identity/conditionalAccess/policies''' + $source | Should -Match 'identity/conditionalAccess/policies/\{0\}''\s+-f\s+\$id' + } + + It 'does not fan out collection results into per-policy requests or sleeps' { + $source | Should -Not -Match 'foreach\s*\(\s*\$cap\s+in\s+\$caps_\s*\)' + $source | Should -Not -Match 'identity/conditionalAccess/policies/\{0\}''\s+-f\s+\$cap\.id' + $source | Should -Not -Match 'Start-Sleep\s+-Milliseconds\s+1000' + } +}