From 427b507bab66f114b07661ac7231a59d46a11c02 Mon Sep 17 00:00:00 2001 From: haydarkozat Date: Fri, 28 Aug 2026 16:06:59 +0300 Subject: [PATCH 1/3] feat: add LAB-01 tenant baseline initializer --- .../scripts/Initialize-TenantBaseline.ps1 | 59 +++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 enterprise-lab/scripts/Initialize-TenantBaseline.ps1 diff --git a/enterprise-lab/scripts/Initialize-TenantBaseline.ps1 b/enterprise-lab/scripts/Initialize-TenantBaseline.ps1 new file mode 100644 index 0000000..ca97b3e --- /dev/null +++ b/enterprise-lab/scripts/Initialize-TenantBaseline.ps1 @@ -0,0 +1,59 @@ +[CmdletBinding(SupportsShouldProcess = $true, ConfirmImpact = 'Medium')] +param() + +$ErrorActionPreference = 'Stop' + +if (-not (Get-Module -ListAvailable -Name Microsoft.Graph.Groups)) { + throw 'Microsoft.Graph.Groups ist nicht installiert. Install-Module Microsoft.Graph -Scope CurrentUser ausführen.' +} + +Import-Module Microsoft.Graph.Groups + +$context = Get-MgContext +if (-not $context) { + throw 'Keine Microsoft-Graph-Verbindung gefunden. Zuerst ./Connect-EntraLab.ps1 ausführen.' +} + +$baselineGroups = @( + [pscustomobject]@{ DisplayName = 'SG-Dept-IT'; Description = 'NordWerk GmbH – IT department security group' }, + [pscustomobject]@{ DisplayName = 'SG-Dept-HR'; Description = 'NordWerk GmbH – HR department security group' }, + [pscustomobject]@{ DisplayName = 'SG-Dept-Finance'; Description = 'NordWerk GmbH – Finance department security group' }, + [pscustomobject]@{ DisplayName = 'SG-Dept-Sales'; Description = 'NordWerk GmbH – Sales department security group' }, + [pscustomobject]@{ DisplayName = 'SG-Dept-Operations'; Description = 'NordWerk GmbH – Operations department security group' }, + [pscustomobject]@{ DisplayName = 'GRP-CA-Pilot'; Description = 'Pilot group for Conditional Access policies' }, + [pscustomobject]@{ DisplayName = 'GRP-Devices-Pilot'; Description = 'Pilot group for Intune device policies' } +) + +$results = foreach ($group in $baselineGroups) { + $escapedName = $group.DisplayName.Replace("'", "''") + $existing = @(Get-MgGroup -Filter "displayName eq '$escapedName'" -Property Id, DisplayName, Description) + + if ($existing.Count -gt 0) { + [pscustomobject]@{ + DisplayName = $group.DisplayName + Status = 'Existing' + ObjectId = $existing[0].Id + Action = 'None' + } + continue + } + + if ($PSCmdlet.ShouldProcess($group.DisplayName, 'Create Microsoft Entra security group')) { + $mailNickname = ($group.DisplayName.ToLowerInvariant() -replace '[^a-z0-9-]', '-') + $created = New-MgGroup ` + -DisplayName $group.DisplayName ` + -Description $group.Description ` + -MailEnabled:$false ` + -MailNickname $mailNickname ` + -SecurityEnabled + + [pscustomobject]@{ + DisplayName = $created.DisplayName + Status = 'Created' + ObjectId = $created.Id + Action = 'Created security group' + } + } +} + +$results | Sort-Object DisplayName From 00458ddd0b058a411468b9f08d44308d83950490 Mon Sep 17 00:00:00 2001 From: haydarkozat Date: Fri, 28 Aug 2026 16:07:20 +0300 Subject: [PATCH 2/3] docs: add LAB-01 tenant setup runbook --- enterprise-lab/docs/LAB-01-TENANT-SETUP.md | 101 +++++++++++++++++++++ 1 file changed, 101 insertions(+) create mode 100644 enterprise-lab/docs/LAB-01-TENANT-SETUP.md diff --git a/enterprise-lab/docs/LAB-01-TENANT-SETUP.md b/enterprise-lab/docs/LAB-01-TENANT-SETUP.md new file mode 100644 index 0000000..f146cd2 --- /dev/null +++ b/enterprise-lab/docs/LAB-01-TENANT-SETUP.md @@ -0,0 +1,101 @@ +# LAB-01 – NordWerk GmbH Tenant Baseline + +## Ziel + +Eine saubere, reproduzierbare Ausgangsbasis für das EntraFlow Enterprise IT Lab schaffen. Dieses Lab wird ausschließlich mit Testkonten und Testgeräten betrieben. + +## 1. Testtenant bereitstellen + +Empfohlener Weg: Microsoft Intune 30-Tage-Testversion. Die Registrierung erstellt einen neuen Microsoft-Entra-Tenant und stellt die für das Intune-Lab benötigte Umgebung bereit. + +Bei der Registrierung: + +- Firmenname: `NordWerk GmbH` +- Land/Region: eigenes tatsächliches Land auswählen +- Tenant-Domain: einen verfügbaren neutralen Lab-Namen verwenden, z. B. `nordwerk-itlab.onmicrosoft.com` +- Das zuerst angelegte Administratorkonto ausschließlich für die Lab-Verwaltung verwenden +- Kennwörter, Tenant-IDs, Client-Secrets und Zertifikate niemals in GitHub speichern + +## 2. PowerShell vorbereiten + +```powershell +pwsh --version +Install-Module Microsoft.Graph -Scope CurrentUser +``` + +Repository klonen bzw. aktualisieren: + +```bash +git clone https://github.com/haydarkozat/entraflow.git +cd entraflow/enterprise-lab/scripts +``` + +Microsoft Graph verbinden: + +```powershell +./Connect-EntraLab.ps1 +``` + +Verbindung kontrollieren: + +```powershell +Get-MgContext | Select-Object TenantId, Account, AuthType, Scopes +``` + +## 3. Baseline-Gruppen zunächst simulieren + +```powershell +./Initialize-TenantBaseline.ps1 -WhatIf +``` + +Beklenen hedef gruplar: + +- `SG-Dept-IT` +- `SG-Dept-HR` +- `SG-Dept-Finance` +- `SG-Dept-Sales` +- `SG-Dept-Operations` +- `GRP-CA-Pilot` +- `GRP-Devices-Pilot` + +## 4. Baseline-Gruppen erstellen + +`-WhatIf` çıktısını kontrol ettikten sonra: + +```powershell +./Initialize-TenantBaseline.ps1 +``` + +İkinci kez çalıştırıldığında mevcut gruplar `Existing` olarak görünmeli ve yinelenen grup oluşturmamalıdır. + +## 5. Doğrulama + +```powershell +Get-MgGroup -All | + Where-Object DisplayName -In @( + 'SG-Dept-IT', + 'SG-Dept-HR', + 'SG-Dept-Finance', + 'SG-Dept-Sales', + 'SG-Dept-Operations', + 'GRP-CA-Pilot', + 'GRP-Devices-Pilot' + ) | + Select-Object DisplayName, Id | + Sort-Object DisplayName +``` + +## 6. Evidence + +LAB-01 ancak aşağıdaki kanıtlar üretildikten sonra tamamlanmış sayılır: + +1. Intune/Entra yönetim merkezinde tenant genel görünümü – tenant ID gibi hassas olmayan bilgiler gerekirse kısmen redakte edilir. +2. Yedi baseline grubunun Entra ID ekran görüntüsü. +3. `Initialize-TenantBaseline.ps1 -WhatIf` terminal çıktısı. +4. Script gerçek çalıştırıldıktan sonraki terminal çıktısı. +5. İkinci çalıştırmada duplicate oluşmadığını gösteren `Existing` çıktısı. +6. `evidence/LAB-01-baseline.md` dosyasında kısa teknik değerlendirme. + +## Güvenlik kararı + +LAB-01 aşamasında Conditional Access politikası etkinleştirilmez. Önce pilot gruplar oluşturulur, erişim senaryoları daha sonraki lablarda test/report-only yaklaşımıyla uygulanır. Global Administrator rolü günlük kullanım için hedef rol değildir; mümkün olan sonraki adımlarda daha dar kapsamlı roller kullanılacaktır. From f94d58d1c86c8981fe407193b44890d71b460b61 Mon Sep 17 00:00:00 2001 From: haydarkozat Date: Fri, 28 Aug 2026 16:07:33 +0300 Subject: [PATCH 3/3] docs: add LAB-01 evidence template --- enterprise-lab/evidence/LAB-01-baseline.md | 47 ++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 enterprise-lab/evidence/LAB-01-baseline.md diff --git a/enterprise-lab/evidence/LAB-01-baseline.md b/enterprise-lab/evidence/LAB-01-baseline.md new file mode 100644 index 0000000..d633785 --- /dev/null +++ b/enterprise-lab/evidence/LAB-01-baseline.md @@ -0,0 +1,47 @@ +# LAB-01 Evidence – Tenant Baseline & RBAC + +**Environment:** NordWerk GmbH – Enterprise IT Lab +**Scenario:** LAB-01 +**Status:** In progress +**Date:** YYYY-MM-DD + +## Problem + +Eine neue Microsoft-Enterprise-Testumgebung benötigt vor Benutzer-, Geräte- und Conditional-Access-Konfigurationen eine kontrollierte Ausgangsbasis mit klaren Gruppen, Pilot-Scope und nachvollziehbaren Namenskonventionen. + +## Maßnahme + +- Microsoft-Entra-/Intune-Testtenant bereitgestellt. +- Fünf Abteilungs-Sicherheitsgruppen angelegt. +- Separate Pilotgruppen für Conditional Access und Intune-Geräte-Policies angelegt. +- Baseline per PowerShell/Microsoft Graph reproduzierbar umgesetzt. +- Schreibende Aktion zunächst mit `-WhatIf` geprüft. + +## Ergebnis + +Nach Abschluss hier dokumentieren: + +- Tenant erfolgreich erreichbar: `Ja/Nein` +- Erwartete Gruppen: `7` +- Tatsächlich vorhandene Gruppen: `` +- Zweiter Script-Lauf ohne Duplikate: `Ja/Nein` +- Verwendete Script-Datei: `Initialize-TenantBaseline.ps1` + +## Sicherheitsaspekt + +- Keine Secrets oder Kennwörter im Repository. +- Conditional Access wird in LAB-01 noch nicht produktiv aktiviert. +- Änderungen zunächst über Pilot-Scope und `-WhatIf` validiert. +- Rollenvergabe nach Least-Privilege-Prinzip weiterentwickelt. + +## Evidence-Dateien + +Nach eigener Durchführung ergänzen: + +- `LAB-01-01-tenant-overview.png` +- `LAB-01-02-baseline-groups.png` +- `LAB-01-03-whatif-terminal.png` +- `LAB-01-04-created-terminal.png` +- `LAB-01-05-idempotency-terminal.png` + +> Vor dem Commit Screenshots auf Tenant-IDs, E-Mail-Adressen, QR-Codes, Secrets, Telefonnummern und andere personenbezogene bzw. sicherheitsrelevante Daten prüfen und nötigenfalls redigieren.