-
Notifications
You must be signed in to change notification settings - Fork 0
/
revokePermissionGroups.ps1
62 lines (49 loc) · 2.01 KB
/
revokePermissionGroups.ps1
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
$config = ConvertFrom-Json $configuration
$aRef = $AccountReference | ConvertFrom-Json
$pRef = $permissionReference | ConvertFrom-Json
$auditLogs = New-Object Collections.Generic.List[PSCustomObject]
$success = $false
try {
Import-Module $config.ModuleLocation -Force
Initialize-KPNBartServiceClients -username $config.UserName -password $Config.password -BaseUrl $config.Url
} catch {
throw("Initialize-KPNBartServiceClients failed with error: $($_.Exception.Message)")
}
$userIdentity = [KPNBartConnectedServices.CommandService.ObjectIdentity]::new()
if (![string]::IsNullOrEmpty($aRef.ObjectGuid)) {
$userIdentity.IdentityType = "guid"
$userIdentity.Value = $aRef.ObjectGuid
} else {
$userIdentity.IdentityType = "UserPrincipalName"
$userIdentity.Value = $aRef.UserPrincipalName
}
$resourceIdentity = [KPNBartConnectedServices.CommandService.ObjectIdentity]::new()
$resourceIdentity.IdentityType = "guid"
$resourceIdentity.Value = "$($pref.reference)"
$ResourceAuthorization = [KPNBartConnectedServices.CommandService.ResourceAuthorizationEnum]::Access
if (-Not($dryRun -eq $true)) {
try {
Set-KPNBartResourceAccess -ResourceAuthorization $ResourceAuthorization -Identity $userIdentity -Add $false -ResourceIdentity $resourceIdentity
$auditLogs.Add([PSCustomObject]@{
Action = "RevokeMembership"
Message = "Permission $($pRef.Reference) removed from account $($aRef.UserPrincipalName)"
IsError = $false
}
)
$Success = $true
} catch {
$auditLogs.Add([PSCustomObject]@{
Action = "RevokeMembership"
Message = "Failed to remove permission $($pRef.Reference) from account $($aRef.UserPrincipalName) Message: $($_.Exception.Message)"
IsError = $true
}
)
}
}
# Send results
$result = [PSCustomObject]@{
Success = $success
AuditLogs = $auditLogs
Account = [PSCustomObject]@{ }
}
Write-Output $result | ConvertTo-Json -Depth 10