Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 101 additions & 0 deletions enterprise-lab/docs/LAB-01-TENANT-SETUP.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
# LAB-01 – NordWerk GmbH Tenant Baseline

## Ziel

Eine saubere, reproduzierbare Ausgangsbasis für das EntraFlow Enterprise IT Lab schaffen. Dieses Lab wird ausschließlich mit Testkonten und Testgeräten betrieben.

## 1. Testtenant bereitstellen

Empfohlener Weg: Microsoft Intune 30-Tage-Testversion. Die Registrierung erstellt einen neuen Microsoft-Entra-Tenant und stellt die für das Intune-Lab benötigte Umgebung bereit.

Bei der Registrierung:

- Firmenname: `NordWerk GmbH`
- Land/Region: eigenes tatsächliches Land auswählen
- Tenant-Domain: einen verfügbaren neutralen Lab-Namen verwenden, z. B. `nordwerk-itlab.onmicrosoft.com`
- Das zuerst angelegte Administratorkonto ausschließlich für die Lab-Verwaltung verwenden
- Kennwörter, Tenant-IDs, Client-Secrets und Zertifikate niemals in GitHub speichern

## 2. PowerShell vorbereiten

```powershell
pwsh --version
Install-Module Microsoft.Graph -Scope CurrentUser
```

Repository klonen bzw. aktualisieren:

```bash
git clone https://github.com/haydarkozat/entraflow.git
cd entraflow/enterprise-lab/scripts
```

Microsoft Graph verbinden:

```powershell
./Connect-EntraLab.ps1
```

Verbindung kontrollieren:

```powershell
Get-MgContext | Select-Object TenantId, Account, AuthType, Scopes
```

## 3. Baseline-Gruppen zunächst simulieren

```powershell
./Initialize-TenantBaseline.ps1 -WhatIf
```

Beklenen hedef gruplar:

- `SG-Dept-IT`
- `SG-Dept-HR`
- `SG-Dept-Finance`
- `SG-Dept-Sales`
- `SG-Dept-Operations`
- `GRP-CA-Pilot`
- `GRP-Devices-Pilot`

## 4. Baseline-Gruppen erstellen

`-WhatIf` çıktısını kontrol ettikten sonra:

```powershell
./Initialize-TenantBaseline.ps1
```

İkinci kez çalıştırıldığında mevcut gruplar `Existing` olarak görünmeli ve yinelenen grup oluşturmamalıdır.

## 5. Doğrulama

```powershell
Get-MgGroup -All |
Where-Object DisplayName -In @(
'SG-Dept-IT',
'SG-Dept-HR',
'SG-Dept-Finance',
'SG-Dept-Sales',
'SG-Dept-Operations',
'GRP-CA-Pilot',
'GRP-Devices-Pilot'
) |
Select-Object DisplayName, Id |
Sort-Object DisplayName
```

## 6. Evidence

LAB-01 ancak aşağıdaki kanıtlar üretildikten sonra tamamlanmış sayılır:

1. Intune/Entra yönetim merkezinde tenant genel görünümü – tenant ID gibi hassas olmayan bilgiler gerekirse kısmen redakte edilir.
2. Yedi baseline grubunun Entra ID ekran görüntüsü.
3. `Initialize-TenantBaseline.ps1 -WhatIf` terminal çıktısı.
4. Script gerçek çalıştırıldıktan sonraki terminal çıktısı.
5. İkinci çalıştırmada duplicate oluşmadığını gösteren `Existing` çıktısı.
6. `evidence/LAB-01-baseline.md` dosyasında kısa teknik değerlendirme.

## Güvenlik kararı

LAB-01 aşamasında Conditional Access politikası etkinleştirilmez. Önce pilot gruplar oluşturulur, erişim senaryoları daha sonraki lablarda test/report-only yaklaşımıyla uygulanır. Global Administrator rolü günlük kullanım için hedef rol değildir; mümkün olan sonraki adımlarda daha dar kapsamlı roller kullanılacaktır.
47 changes: 47 additions & 0 deletions enterprise-lab/evidence/LAB-01-baseline.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
# LAB-01 Evidence – Tenant Baseline & RBAC

**Environment:** NordWerk GmbH – Enterprise IT Lab
**Scenario:** LAB-01
**Status:** In progress
**Date:** YYYY-MM-DD

## Problem

Eine neue Microsoft-Enterprise-Testumgebung benötigt vor Benutzer-, Geräte- und Conditional-Access-Konfigurationen eine kontrollierte Ausgangsbasis mit klaren Gruppen, Pilot-Scope und nachvollziehbaren Namenskonventionen.

## Maßnahme

- Microsoft-Entra-/Intune-Testtenant bereitgestellt.
- Fünf Abteilungs-Sicherheitsgruppen angelegt.
- Separate Pilotgruppen für Conditional Access und Intune-Geräte-Policies angelegt.
- Baseline per PowerShell/Microsoft Graph reproduzierbar umgesetzt.
- Schreibende Aktion zunächst mit `-WhatIf` geprüft.

## Ergebnis

Nach Abschluss hier dokumentieren:

- Tenant erfolgreich erreichbar: `Ja/Nein`
- Erwartete Gruppen: `7`
- Tatsächlich vorhandene Gruppen: `<Anzahl>`
- Zweiter Script-Lauf ohne Duplikate: `Ja/Nein`
- Verwendete Script-Datei: `Initialize-TenantBaseline.ps1`

## Sicherheitsaspekt

- Keine Secrets oder Kennwörter im Repository.
- Conditional Access wird in LAB-01 noch nicht produktiv aktiviert.
- Änderungen zunächst über Pilot-Scope und `-WhatIf` validiert.
- Rollenvergabe nach Least-Privilege-Prinzip weiterentwickelt.

## Evidence-Dateien

Nach eigener Durchführung ergänzen:

- `LAB-01-01-tenant-overview.png`
- `LAB-01-02-baseline-groups.png`
- `LAB-01-03-whatif-terminal.png`
- `LAB-01-04-created-terminal.png`
- `LAB-01-05-idempotency-terminal.png`

> Vor dem Commit Screenshots auf Tenant-IDs, E-Mail-Adressen, QR-Codes, Secrets, Telefonnummern und andere personenbezogene bzw. sicherheitsrelevante Daten prüfen und nötigenfalls redigieren.
59 changes: 59 additions & 0 deletions enterprise-lab/scripts/Initialize-TenantBaseline.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
[CmdletBinding(SupportsShouldProcess = $true, ConfirmImpact = 'Medium')]
param()

$ErrorActionPreference = 'Stop'

if (-not (Get-Module -ListAvailable -Name Microsoft.Graph.Groups)) {
throw 'Microsoft.Graph.Groups ist nicht installiert. Install-Module Microsoft.Graph -Scope CurrentUser ausführen.'
}

Import-Module Microsoft.Graph.Groups

$context = Get-MgContext
if (-not $context) {
throw 'Keine Microsoft-Graph-Verbindung gefunden. Zuerst ./Connect-EntraLab.ps1 ausführen.'
}

$baselineGroups = @(
[pscustomobject]@{ DisplayName = 'SG-Dept-IT'; Description = 'NordWerk GmbH – IT department security group' },
[pscustomobject]@{ DisplayName = 'SG-Dept-HR'; Description = 'NordWerk GmbH – HR department security group' },
[pscustomobject]@{ DisplayName = 'SG-Dept-Finance'; Description = 'NordWerk GmbH – Finance department security group' },
[pscustomobject]@{ DisplayName = 'SG-Dept-Sales'; Description = 'NordWerk GmbH – Sales department security group' },
[pscustomobject]@{ DisplayName = 'SG-Dept-Operations'; Description = 'NordWerk GmbH – Operations department security group' },
[pscustomobject]@{ DisplayName = 'GRP-CA-Pilot'; Description = 'Pilot group for Conditional Access policies' },
[pscustomobject]@{ DisplayName = 'GRP-Devices-Pilot'; Description = 'Pilot group for Intune device policies' }
)

$results = foreach ($group in $baselineGroups) {
$escapedName = $group.DisplayName.Replace("'", "''")
$existing = @(Get-MgGroup -Filter "displayName eq '$escapedName'" -Property Id, DisplayName, Description)

if ($existing.Count -gt 0) {
[pscustomobject]@{
DisplayName = $group.DisplayName
Status = 'Existing'
ObjectId = $existing[0].Id
Action = 'None'
}
continue
}

if ($PSCmdlet.ShouldProcess($group.DisplayName, 'Create Microsoft Entra security group')) {
$mailNickname = ($group.DisplayName.ToLowerInvariant() -replace '[^a-z0-9-]', '-')
$created = New-MgGroup `
-DisplayName $group.DisplayName `
-Description $group.Description `
-MailEnabled:$false `
-MailNickname $mailNickname `
-SecurityEnabled

[pscustomobject]@{
DisplayName = $created.DisplayName
Status = 'Created'
ObjectId = $created.Id
Action = 'Created security group'
}
}
}

$results | Sort-Object DisplayName
Loading