add: New testing function

This commit is contained in:
DrIOS
2024-05-28 17:08:04 -05:00
parent 8505439516
commit 129bb33a99
55 changed files with 691 additions and 804 deletions

View File

@@ -15,51 +15,39 @@ function Test-GuestUsersBiweeklyReview {
process {
# 1.1.4 (L1) Ensure Guest Users are reviewed at least biweekly
try {
# Retrieve guest users from Microsoft Graph
# Connect-MgGraph -Scopes "User.Read.All"
$guestUsers = Get-MgUser -All -Filter "UserType eq 'Guest'"
# Prepare failure reasons and details based on compliance
$failureReasons = if ($guestUsers) {
"Guest users present: $($guestUsers.Count)"
}
else {
"N/A"
}
# Retrieve guest users from Microsoft Graph
# Connect-MgGraph -Scopes "User.Read.All"
$guestUsers = Get-MgUser -All -Filter "UserType eq 'Guest'"
$details = if ($guestUsers) {
$auditCommand = "Get-MgUser -All -Property UserType,UserPrincipalName | Where {`$_.UserType -ne 'Member'} | Format-Table UserPrincipalName, UserType"
"Manual review required. To list guest users, run: `"$auditCommand`"."
}
else {
"No guest users found."
}
# Create and populate the CISAuditResult object
$auditResult = [CISAuditResult]::new()
$auditResult.CISControl = "5.1, 5.3"
$auditResult.CISDescription = "Establish and Maintain an Inventory of Accounts, Disable Dormant Accounts"
$auditResult.Rec = "1.1.4"
$auditResult.RecDescription = "Ensure Guest Users are reviewed at least biweekly"
$auditResult.ELevel = "E3"
$auditResult.ProfileLevel = "L1"
$auditResult.IG1 = $true
$auditResult.IG2 = $true
$auditResult.IG3 = $true
$auditResult.CISControlVer = 'v8'
$auditResult.Result = -not $guestUsers
$auditResult.Details = $details
$auditResult.FailureReason = $failureReasons
$auditResult.Status = if ($guestUsers) { "Fail" } else { "Pass" }
# Prepare failure reasons and details based on compliance
$failureReasons = if ($guestUsers) {
"Guest users present: $($guestUsers.Count)"
}
catch {
$auditResult = [CISAuditResult]::new()
$auditResult.Status = "Error"
$auditResult.Result = $false
$auditResult.Details = "Error while attempting to check guest users. Error message: $($_.Exception.Message)"
$auditResult.FailureReason = "An error occurred during the audit check."
else {
"N/A"
}
$details = if ($guestUsers) {
$auditCommand = "Get-MgUser -All -Property UserType,UserPrincipalName | Where {`$_.UserType -ne 'Member'} | Format-Table UserPrincipalName, UserType"
"Manual review required. To list guest users, run: `"$auditCommand`"."
}
else {
"No guest users found."
}
# Create and populate the CISAuditResult object
$params = @{
Rec = "1.1.4"
Result = -not $guestUsers
Status = if ($guestUsers) { "Fail" } else { "Pass" }
Details = $details
FailureReason = $failureReasons
RecDescription = "Ensure Guest Users are reviewed at least biweekly"
CISControl = "5.1, 5.3"
CISDescription = "Establish and Maintain an Inventory of Accounts, Disable Dormant Accounts"
}
$auditResult = Initialize-CISAuditResult @params
}
end {