Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
120 commits
Select commit Hold shift + click to select a range
1b5b918
Feature-41033
Manoj-Kesana Jul 2, 2026
a5d5191
initial commit
praneeth-0000 Jul 9, 2026
2055d36
removed unnecessary code
praneeth-0000 Jul 10, 2026
f829035
Refactored the code
Manoj-Kesana Jul 13, 2026
b76fbc7
add skip condition for USGov Env and Security Reader role in docs
praneeth-0000 Jul 13, 2026
c07d4d7
Potential fix for pull request finding
Manoj-Kesana Jul 13, 2026
3d07cc8
Potential fix for pull request finding
Manoj-Kesana Jul 13, 2026
3d991ef
refactored code
praneeth-0000 Jul 13, 2026
f06fb56
Fix ambigious values and Remove readme.md (moving to separate PR)
praneeth-0000 Jul 13, 2026
4d8c226
chore: restore readme.md to dev state (moving to separate PR)
praneeth-0000 Jul 13, 2026
4483dbd
Fix ambigious values for Q1, Q2 & Q3
praneeth-0000 Jul 13, 2026
5e8f4d0
Feedback addressed
Manoj-Kesana Jul 13, 2026
e500905
add ZAP exception scope
praneeth-0000 Jul 14, 2026
a3ec2b7
initial commit
sandeepjha000 Jul 15, 2026
c82288f
Implement anti-spam hosted content filter policy assessment with spec…
sandeepjha000 Jul 16, 2026
7635f9e
uodate(41034): Investigate message formatting and add portal-linked t…
sandeepjha000 Jul 16, 2026
453ad12
Resolving copilot comments
sandeepjha000 Jul 17, 2026
de3b8d0
Correct whitespace in Test-Assessment.41034.ps1
alexandair Jul 17, 2026
0f7af1a
Initial draft
Manoj-Kesana Jul 17, 2026
e5a89c9
refactored code acc to updated spec
praneeth-0000 Jul 20, 2026
dfd18d4
fixed issues
praneeth-0000 Jul 20, 2026
770d98a
removed unused variables
praneeth-0000 Jul 20, 2026
2637b82
removed copilot comments
praneeth-0000 Jul 20, 2026
53defa8
resolved builtin safe links policy edge case
praneeth-0000 Jul 20, 2026
b58b026
fix ambigious value issue
praneeth-0000 Jul 20, 2026
6afd769
Refactored
Manoj-Kesana Jul 20, 2026
bef8386
unused
Manoj-Kesana Jul 20, 2026
cecfc9b
Potential fix for pull request finding
Manoj-Kesana Jul 20, 2026
6600400
Implement error sanitization and reporting improvements in assessment…
alexandair Jul 20, 2026
5d95210
Enhance error sanitization by adding query secret redaction and impro…
alexandair Jul 20, 2026
adf6fb3
fixed PR comments(41034)
sandeepjha000 Jul 21, 2026
90794e7
Merge branch 'feature-41034' of https://github.com/microsoft/zerotrus…
sandeepjha000 Jul 21, 2026
4e613bd
Refactor result handling to improve clarity and error handling
alexandair Jul 21, 2026
63a03f2
Add tests for advanced hunting query and error handling
alexandair Jul 21, 2026
ac7506b
Fix whitespaces
alexandair Jul 21, 2026
9a761d2
Feedback addressed
Manoj-Kesana Jul 21, 2026
b017427
update dev branch with release changes (#1430)
astaykov Jul 21, 2026
a10bd37
Add test to preserve count above 32-bit integer limit
alexandair Jul 21, 2026
081cf33
# SecOps - 41211 - Auditing and health monitoring is enabled for Micr…
aahmed-spec Jul 21, 2026
71200d6
SecOps - 41116 - Threat hunting against Email and Collaboration table…
astaykov Jul 21, 2026
52a7aae
SecOps - 41034 - Anti-spam (hosted content filter) policies are confi…
astaykov Jul 21, 2026
3e04fe4
made changes as per Alek's suggestions
aahmed-spec Jul 22, 2026
b49e21a
Updates to overview page - header and footer
astaykov Jul 22, 2026
e802480
updated code
ashwinikarke Jul 22, 2026
3626e52
updated code
ashwinikarke Jul 22, 2026
91e483a
updated code
ashwinikarke Jul 22, 2026
4304520
updated code
ashwinikarke Jul 22, 2026
56cf1e4
Addresses #1434: This check cannot be reliably performed in the conte…
astaykov Jul 22, 2026
dae5ac8
made changes as per Alek's suggestions
aahmed-spec Jul 22, 2026
6af4692
made changes as per Alek's suggestions
aahmed-spec Jul 22, 2026
773d053
Addresses #1434: retire check 35037 (#1437)
astaykov Jul 22, 2026
0bb98a8
Updates to overview page - header and footer (#1435)
astaykov Jul 22, 2026
239d9fd
Add total diagnostic settings count to output and update table format…
alexandair Jul 22, 2026
f270127
resolved PR comments
ashwinikarke Jul 23, 2026
c05337e
resolved PR comments
ashwinikarke Jul 23, 2026
c28b05a
SecOps - 41211 - Auditing and health monitoring is enabled for Micros…
astaykov Jul 23, 2026
43c8542
resolved PR comments
ashwinikarke Jul 23, 2026
b2bfc96
Moving Infrastructure, SecOps and AI out of Preview, while preserving…
astaykov Jul 23, 2026
a43de9d
Implement error sanitization and reporting improvements in tests (#1426)
astaykov Jul 23, 2026
2f6caeb
foundation for new report layout while keeping the "classic" around.
astaykov Jul 23, 2026
578b467
fix: align Invoke-ZtTests preview-filter comment with actual logic
Copilot Jul 23, 2026
fab0a85
addressing GHCP comment on the preview gate logic.
astaykov Jul 23, 2026
cd6ab00
Merge branch 'astaykov/feature-preview-flag' of https://github.com/mi…
astaykov Jul 23, 2026
adf4c74
resolved PR comments
ashwinikarke Jul 23, 2026
bd152e4
initial commit
praneeth-0000 Jul 21, 2026
c9940bd
refactored code
praneeth-0000 Jul 21, 2026
4a40afb
removed biggest gap section, aligned status labels
praneeth-0000 Jul 23, 2026
8a2d708
fixed logic which displays status
praneeth-0000 Jul 23, 2026
5c2eda8
Network 25375 - The tenant holds the licenses required to operate Glo…
astaykov Jul 23, 2026
749de80
WIP : new desgn
astaykov Jul 23, 2026
52f8263
Moving Infrastructure, SecOps and AI out of Preview (#1441)
astaykov Jul 24, 2026
9e6047c
SecOps - 41209 - User and Entity Behavior Analytics (UEBA) is enabled…
aahmed-spec Jul 24, 2026
4e3afd1
identity overview
astaykov Jul 24, 2026
904abd9
made changes as per copilot's suggestions
aahmed-spec Jul 24, 2026
0e2c45e
fixed alignment
praneeth-0000 Jul 24, 2026
4875b28
initial commit
praneeth-0000 Jul 24, 2026
ba733db
Identity + devices almost ready
astaykov Jul 24, 2026
93b4ba6
Fixes
Manoj-Kesana Jul 27, 2026
b215c3c
made changes as per Alek's suggestions
aahmed-spec Jul 27, 2026
61065b4
made changes as per Alek's suggestions
aahmed-spec Jul 27, 2026
9e1257b
removed sku column and updated header link
praneeth-0000 Jul 27, 2026
c2ca38c
add description and notes
praneeth-0000 Jul 27, 2026
45f903f
Made required changes
Manoj-Kesana Jul 27, 2026
8157b79
updated code according to spec
praneeth-0000 Jul 27, 2026
78fb685
seperate safelinks policy and rule query error wrt built in policy
praneeth-0000 Jul 27, 2026
8c306b0
added explicit variable for exception
praneeth-0000 Jul 27, 2026
fd7bbf7
Feedback addressed
Manoj-Kesana Jul 27, 2026
6437fcb
fixed aleks comments
praneeth-0000 Jul 28, 2026
e886006
fixed aleks comments
praneeth-0000 Jul 28, 2026
73e3906
SecOps - 41209 - User and Entity Behavior Analytics (UEBA) is enabled…
astaykov Jul 28, 2026
b3041f6
updating the classic template
astaykov Jul 28, 2026
100e1c6
SecOps - 41215 - Microsoft Security Copilot capacity (Security Comput…
aahmed-spec Jul 28, 2026
98c97a4
updated pass message
praneeth-0000 Jul 28, 2026
48a92e0
SecOps - 41033 - Anti-phishing policies in Microsoft Defender for Off…
astaykov Jul 28, 2026
ddf5f32
SecOps - 41114 - Microsoft Teams protection policies are configured t…
astaykov Jul 28, 2026
fb58e39
Network - 27024 - HTTP DDoS protection rule set is enabled in Azure F…
astaykov Jul 28, 2026
9cd0abb
Add a Pester test
alexandair Jul 28, 2026
6dffa93
Intial draft
Manoj-Kesana Jul 29, 2026
9e53f3a
Network - 27023 - Azure workloads are protected across the inbound, o…
astaykov Jul 29, 2026
a271719
made changes as per Alek's suggestions
aahmed-spec Jul 29, 2026
4ddb12b
Merge branch 'dev' of https://github.com/microsoft/zerotrustassessmen…
astaykov Jul 29, 2026
e69415b
updating templates and reports
astaykov Jul 29, 2026
1ed6cfe
Heading
Manoj-Kesana Jul 29, 2026
f9bcdab
add yellow color to circle chart ring when fail % is less than 80
praneeth-0000 Jul 29, 2026
1557cc2
Potential fix for pull request finding
Manoj-Kesana Jul 29, 2026
862dc4e
add agent Total agents and Active users in overview page
praneeth-0000 Jul 29, 2026
54fe45c
Feedback addressed
Manoj-Kesana Jul 30, 2026
0b35a0e
link
Manoj-Kesana Jul 30, 2026
b8ae5fe
made changes as per Alek's suggestions
aahmed-spec Jul 30, 2026
19001aa
SecOps - 41052 - Application control (WDAC / App Control for Business…
astaykov Jul 30, 2026
1d8f8d6
updated azure network chart according to spec update
praneeth-0000 Jul 30, 2026
79e7367
move and align azure network chart to src-current
praneeth-0000 Jul 30, 2026
c1b7144
aligned circle chart in src-current
praneeth-0000 Jul 30, 2026
1b12e22
SecOps - 41215 - Microsoft Security Copilot capacity (Security Comput…
tdetzner Jul 30, 2026
9e9338c
add pester test for agent overview function
praneeth-0000 Jul 30, 2026
58fa6ad
Fix preview report validation failures
alexandair Jul 30, 2026
beca437
Merge branch 'astaykov/preview-report' of https://github.com/microsof…
praneeth-0000 Jul 30, 2026
b0a160e
fix typo in outbound plane
praneeth-0000 Jul 31, 2026
79e32d6
UI - Add total agent & active user count, fix azure network security …
tdetzner Jul 31, 2026
bcd41bb
Astaykov/preview report DO NOT REVIEW | DO NOT MERGE (#1464)
astaykov Jul 31, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ Connect-ZtAssessment
Invoke-ZtAssessment
```

By default, `Invoke-ZtAssessment` now runs all current pillars: Identity, Devices, Network, Data, Infrastructure, SecOps, and AI. The `-Preview` switch is reserved for future preview-only features.

## Infrastructure Pillar Scope

Infrastructure pillar results are based on Microsoft Defender for Cloud recommendations and only include Azure subscriptions tagged with `ZeroTrustAssessment:Infrastructure`.
Expand Down
174 changes: 174 additions & 0 deletions code-tests/commands/Add-ZtAgentOverview.Tests.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,174 @@
Describe "Add-ZtAgentOverview" {
BeforeAll {
$here = $PSScriptRoot
$srcRoot = Join-Path $here "../../src/powershell"

if (-not (Get-Command Write-PSFMessage -ErrorAction SilentlyContinue)) {
function global:Write-PSFMessage {
param($Level, $Message, $Tag)
}
}

if (-not (Get-Command Write-ZtProgress -ErrorAction SilentlyContinue)) {
function global:Write-ZtProgress {
param($Activity, $Status)
}
}

if (-not (Get-Command Invoke-ZtGraphRequest -ErrorAction SilentlyContinue)) {
function global:Invoke-ZtGraphRequest {
param(
$RelativeUri,
$ApiVersion,
$Select,
$Filter,
$Top,
$QueryParameters,
$ConsistencyLevel,
$Headers,
[switch] $DisablePaging,
[switch] $DisableCache
)
}
}

if (-not (Get-Command Add-ZtTenantInfo -ErrorAction SilentlyContinue)) {
function global:Add-ZtTenantInfo {
param($Name, $Value)
}
}

. (Join-Path $srcRoot "private/tenantinfo/ai/Add-ZtAgentOverview.ps1")
}

BeforeEach {
$script:tenantInfo = $null
$script:activeUserFilter = $null

Mock Write-PSFMessage {}
Mock Write-ZtProgress {}
Mock Add-ZtTenantInfo {
param($Name, $Value)
$script:tenantInfo = [pscustomobject]@{
Name = $Name
Value = $Value
}
}
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -eq 'servicePrincipals' } -MockWith {
@{ '@odata.count' = 42; value = @(@{ id = 'agent-1' }) }
}
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -like 'auditLogs/getSummarizedNonInteractiveSignIns*' } -MockWith {
$script:activeUserFilter = $Filter
@(
[pscustomobject]@{ userPrincipalName = 'alice@contoso.com' }
[pscustomobject]@{ userPrincipalName = 'Alice@Contoso.com' }
[pscustomobject]@{ userPrincipalName = 'bob@contoso.com' }
[pscustomobject]@{ userPrincipalName = $null }
[pscustomobject]@{ userPrincipalName = ' ' }
)
}
}

It "Should collect total agents and unique active users using the expected Graph requests" {
Add-ZtAgentOverview

$script:tenantInfo.Name | Should -Be 'AgentOverview'
$script:tenantInfo.Value.TotalAgents | Should -Be 42
$script:tenantInfo.Value.TotalAgents | Should -BeOfType [int]
$script:tenantInfo.Value.ActiveUsers | Should -Be 2
$script:tenantInfo.Value.ActiveUsers | Should -BeOfType [int]
$startMatch = [regex]::Match($script:activeUserFilter, 'firstSignInDateTime ge (?<Start>\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z)')
$endMatch = [regex]::Match($script:activeUserFilter, 'firstSignInDateTime lt (?<End>\d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z)')
$startMatch.Success | Should -BeTrue
$endMatch.Success | Should -BeTrue
$lookbackStart = [datetimeoffset]::ParseExact($startMatch.Groups['Start'].Value, 'yyyy-MM-ddTHH:mm:ssZ', [Globalization.CultureInfo]::InvariantCulture)
$lookbackEnd = [datetimeoffset]::ParseExact($endMatch.Groups['End'].Value, 'yyyy-MM-ddTHH:mm:ssZ', [Globalization.CultureInfo]::InvariantCulture)
($lookbackEnd - $lookbackStart).TotalDays | Should -Be 30

Should -Invoke Invoke-ZtGraphRequest -Times 1 -Exactly -ParameterFilter {
$RelativeUri -eq 'servicePrincipals' -and
$ApiVersion -eq 'v1.0' -and
$Select -eq 'id' -and
$Filter -eq "(isof('microsoft.graph.agentIdentity') OR (tags/any(p:startswith(p, 'power-virtual-agents-')) OR tags/any(p:p eq 'AgenticInstance')))" -and
$Top -eq 1 -and
$QueryParameters['$count'] -eq 'true' -and
$ConsistencyLevel -eq 'eventual' -and
$DisablePaging -and
$DisableCache
}
Should -Invoke Invoke-ZtGraphRequest -Times 1 -Exactly -ParameterFilter {
$RelativeUri -eq "auditLogs/getSummarizedNonInteractiveSignIns(aggregationWindow='d1')" -and
$ApiVersion -eq 'beta' -and
$Select -eq 'userPrincipalName' -and
$Filter -match "agent/agentType eq 'agenticAppInstance'" -and
$Filter -match "agent/agentSubjectType ne 'agentIDuser'" -and
$Filter -match 'firstSignInDateTime ge \d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z' -and
$Filter -match 'firstSignInDateTime lt \d{4}-\d{2}-\d{2}T\d{2}:\d{2}:\d{2}Z' -and
$Top -eq 1000 -and
$QueryParameters['$orderby'] -eq 'firstSignInDateTime desc' -and
$Headers.Prefer -eq 'include-unknown-enum-members' -and
$DisableCache
}
Should -Invoke Add-ZtTenantInfo -Times 1 -Exactly -ParameterFilter { $Name -eq 'AgentOverview' }
Should -Invoke Write-PSFMessage -Times 0 -Exactly
Should -Invoke Write-ZtProgress -Times 1 -Exactly -ParameterFilter { $Status -eq 'Processing' }
Should -Invoke Write-ZtProgress -Times 1 -Exactly -ParameterFilter { $Status -eq 'Completed' }
}

It "Should emit zero values when Graph returns no agents or sign-ins" {
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -eq 'servicePrincipals' } -MockWith {
@{ '@odata.count' = 0; value = @() }
}
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -like 'auditLogs/getSummarizedNonInteractiveSignIns*' } -MockWith { @() }

Add-ZtAgentOverview

$script:tenantInfo.Value.TotalAgents | Should -Be 0
$script:tenantInfo.Value.ActiveUsers | Should -Be 0
Should -Invoke Write-PSFMessage -Times 0 -Exactly
}

It "Should preserve active users when the total-agent query fails" {
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -eq 'servicePrincipals' } -MockWith {
throw 'Agent count request failed'
}

Add-ZtAgentOverview

$script:tenantInfo.Value.TotalAgents | Should -BeNullOrEmpty
$script:tenantInfo.Value.ActiveUsers | Should -Be 2
Should -Invoke Invoke-ZtGraphRequest -Times 1 -Exactly -ParameterFilter { $RelativeUri -like 'auditLogs/getSummarizedNonInteractiveSignIns*' }
Should -Invoke Write-PSFMessage -Times 1 -Exactly -ParameterFilter {
$Level -eq 'Warning' -and $Message -eq 'Unable to retrieve the total agent count from Microsoft Graph.'
}
}

It "Should preserve total agents when the active-user query fails" {
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -like 'auditLogs/getSummarizedNonInteractiveSignIns*' } -MockWith {
throw 'Active user request failed'
}

Add-ZtAgentOverview

$script:tenantInfo.Value.TotalAgents | Should -Be 42
$script:tenantInfo.Value.ActiveUsers | Should -BeNullOrEmpty
Should -Invoke Write-PSFMessage -Times 1 -Exactly -ParameterFilter {
$Level -eq 'Warning' -and $Message -eq 'Unable to retrieve active agent users from Microsoft Graph.'
}
Should -Invoke Add-ZtTenantInfo -Times 1 -Exactly -ParameterFilter { $Name -eq 'AgentOverview' }
}

It "Should treat a missing agent count as a failed total-agent query" {
Mock Invoke-ZtGraphRequest -ParameterFilter { $RelativeUri -eq 'servicePrincipals' } -MockWith {
@{ value = @() }
}

Add-ZtAgentOverview

$script:tenantInfo.Value.TotalAgents | Should -BeNullOrEmpty
$script:tenantInfo.Value.ActiveUsers | Should -Be 2
Should -Invoke Write-PSFMessage -Times 1 -Exactly -ParameterFilter {
$Level -eq 'Warning' -and $Message -eq 'Unable to retrieve the total agent count from Microsoft Graph.'
}
}
}
Loading