Harness: -Credential finds a Microsoft Entra account's session - #6
Merged
Merged
Conversation
…ssion The launcher looked in 'query user' for the credential's user name taken apart as text. Windows calls an Entra account AzureAD\<display name without spaces, cut at 20 characters>, which is neither the sign-in name nor a part of it, so a credential naming user@domain was refused or fell back to the stored-password task. Measured on the joined lab device with a user signed in for the purpose; this is the 'query user' item left open in #4. Resolve-IslAccount asks Windows for the SID behind the name, trying AzureAD\ in front of a sign-in name, and for the name Windows gives that SID. The session is matched on that name, the interactive task is registered for it, which is the only name the scheduler took, and the run folder is granted by SID.
…rAction Stop on 5.1 Windows PowerShell turns a native command's redirected stderr into error records; with the caller's preference at Stop the first one ended Grant-IslFolderAccess with icacls' bare line. The 5.1 gate caught it through the new test; the function now reads icacls' output under Continue and reports the account and the folder.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes
-Credentialon the fiveInvoke-Intune*Testcommands for Microsoft Entra accounts. The launcher could not find such an account's session unless the credential happened to name it the way Windows does, and failed or fell back to the stored-password task otherwise.This closes the item #4 left open under "Not changed" as the
query userlong-name case, carried forward in #5. Measured on a device, the name length was never the problem: the parser reads the output correctly. The name being looked for was the wrong one.ModuleVersionis not bumped; the change is under Unreleased in the changelog.What was measured
On the Entra joined lab device (VM 125, 2026-10-05), with a tenant user created for the purpose and signed in at the console:
isl-verylongusername-test01@4nlnm3.onmicrosoft.com(27 characters before the@)AzureAD\IslVerylongdisplaynabetar@..., running asAzureAD\JeffStuhr.query userprints that name in lower case. The user name column is 22 characters wide and the name stopped at 20, so the parser's split held. No name longer than 20 characters was seen.NTAccount.TranslateresolvesAzureAD\<sign-in name>andAzureAD\<Windows name>to the account's SID. The bare sign-in name, the bare Windows name andAzureAD\<part before the @>do not resolve.Cause
Invoke-IslProcesstook the credential's user name apart as text (the part after a backslash, or before an@) and looked for that inquery user. That works for a local account, whose Windows name is that text, and cannot work for an Entra account.Changes
Private/Resolve-IslAccount.ps1(new). Asks Windows for the SID behind the credential's user name, tryingAzureAD\in front of a sign-in name that does not resolve as given, and for the name Windows gives that SID. Returns nothing when the name does not resolve; the caller then works with the name as before.Invoke-IslProcess. Matches the session on the resolved Windows name and registers the interactive task for it. The result'sUserNameandRunAsstill carry the credential's name as given. The stored-password path is unchanged.Grant-IslFolderAccess. Grants the run folder by SID when the account resolves, since a sign-in name is not a nameicaclslooks up.Grant-IslFolderAccess, error message. Under-ErrorAction Stopon Windows PowerShell 5.1 a refused grant ended withicacls' bare line instead of the message naming the account and the folder, because 5.1 turns a native command's redirected stderr into error records. The 5.1 gate caught this through the new test on the first push; the function now reads the output underContinue.Validation/Findings.md("The harness as another account") replaces the "not measured" note with the table above. The README and the-Credentialhelp of the five harness commands say how an Entra account can be named. MAML rebuilt.Before and after on the device
The module run as SYSTEM through the guest agent, the same probe script and the same signed-in user,
-Credentialnaming the account three ways:user@domainAzureAD\user@domainAzureAD\IslVerylongdisplaynaEvery successful run reported
who=AzureAD\IslVerylongdisplayna session=2 interactive=TruewithRunAsending in(Interactive), and left no scheduled task and no run folder behind.Verification
query userline as the device printed it.Build/Publish-Module.ps1 -WhatIfstages and verifies the package with the new private file in it.Not changed
query user. That was true before and is not addressed here.