15 Commits
Author SHA1 Message Date
RachelElysia 0585ab68d1 Website: Handle unexpected responses from Microsoft's compliance and Graph APIs (#50015)
## Issue

#50013

## Description

The Microsoft compliance proxy controller
(`website/api/controllers/microsoft-proxy/receive-redirect-from-microsoft.js`)
called `JSON.parse` on response bodies from Microsoft's Partner
Compliance and Graph APIs without checking for empty bodies or
unexpected response shapes. When Microsoft returned an unexpected
response — for example, a 2xx status with an empty body, which can
happen on partial-setup tenant states or when API permissions on the
enterprise app haven't been fully consented — the controller threw a raw
`SyntaxError: Unexpected end of JSON input` that surfaced verbatim in
the Fleet UI as the `setup_error` string, giving admins a Node.js stack
trace instead of a useful message.

Changes:
- Added explicit empty-body checks before `JSON.parse` at both
API-response parse sites, with a friendly `setup_error` message pointing
at the likely causes (partial setup / missing API permissions).
- On parse failure, expanded the diagnostic log to include response
status code, body length, and a 200-char body snippet so we can diagnose
future occurrences from server logs instead of asking admins to
reproduce.
- Added defensive checks on `parsedPoliciesResponse.value` and
`parsedGroupResponse.value` before indexing — previously
`parsedPoliciesResponse.value[0].Id` would throw `TypeError` if
Microsoft returned a well-formed response missing the expected shape.

**Note for reviewers:** The new `sails.log.warn` calls interpolate the
runtime tenant ID (`informationAboutThisTenant.entraTenantId`) — same
pattern as the existing log at line 209 that logs `fleetInstanceUrl`.
Heroku logs will contain tenant IDs when these error paths fire, which
is intentional so infra can grep by tenant when triaging. If we'd rather
rely on request-correlation IDs and keep tenant IDs out of logs, happy
to make that a follow-up.

## Screenrecording


## Testing
- [ ] Sanity-checked locally by inducing an empty response body
- [ ] Verified no changes to the happy-path flow
- [ ] Verified existing setup_error strings that the Fleet UI checks for
(admin-did-not-consent, missing-conditional-access-group) are unchanged

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved Microsoft integration setup handling when API responses are
empty, invalid, or missing expected data.
* Added clearer setup error messages for missing policies or the “Fleet
conditional access” group.
* Enhanced diagnostics to help identify response-related setup failures.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-28 11:04:08 -05:00
Lucas Manuel RodriguezandEric df36ce891a Website: don't require an API key on Microsoft compliance proxy requests (#49434)
**Related issue:** Resolves #47699

## Testing

- [x] QA'd all new/changed functionality manually

## What & why

Entra conditional access is becoming available to self-hosted Fleet
Premium instances, which don't have the shared `MS-API-KEY` that
cloud-managed customers use. This makes the `microsoft-proxy/*`
endpoints reachable without that key by dropping the `is-cloud-customer`
policy gate (and the now-unused shared-secret config comments / policy
file).

A replacement auth mechanism for the proxy is tracked separately in
#47702.

> Split out of #49414 so the website change can ship independently.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Security / Access Control**
* Updated Microsoft proxy access handling to bypass the prior
cloud-customer check for matching requests.
* **Configuration**
* Removed unused cloud-customer compliance proxy shared-secret settings.
* **Bug Fixes**
* Improved compliance partner tenant creation by detecting existing
tenants using the provided Entra tenant ID and corrected the success
message text.
* **Data Model**
* Removed uniqueness enforcement for stored fleet instance URLs to
prevent avoidable conflicts.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2026-07-20 15:38:28 -05:00
Eric 1c89b79dbe Website: Fix typo in ms compliance proxy inputs (#44258)
Closes: https://github.com/fleetdm/confidential/issues/15631

Changes:
- Fixed a typo in the inputs on three microsoft proxy endpoints

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Corrected input validation to properly enforce required fields in
Microsoft proxy endpoints.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-27 16:35:20 -05:00
EricandLucas Manuel Rodriguez 5a266bfaca Website: Update Microsoft proxy endpoint to support windows devices (#41780)
For: https://github.com/fleetdm/fleet/issues/39489

Changes:
- Updated the `update-one-devices-compliance-status` Microsoft proxy
endpoint to support compliance status updates for Windows devices
enrolled in Entra.

---------

Co-authored-by: Lucas Manuel Rodriguez <lucas@fleetdm.com>
2026-03-17 13:03:32 -05:00
Eric 56f01f0170 Website: Update create-compliance-partner-tenant (#36528)
Changes:
- Updated an error handler in the the website's
create-compliance-partner-tenant action
2025-12-01 16:10:17 -06:00
Eric fddd4bac85 Website: Update create-compliance-partner-tenant error handling (#36366)
Closes: https://github.com/fleetdm/fleet/issues/36356

Changes:
- updated the website's `create-compliance-partner-tenant` microsoft
proxy endpoint to return a `connectionAlreadyExists` response when a
uniqueness error is returned by the database adapter.
2025-11-26 16:29:05 -06:00
Eric a12616a781 Website: Update Microsoft proxy redirect error handling (#35675)
Related to: https://github.com/fleetdm/confidential/issues/13036

Changes:
- updated the receive-redirect-from-microsoft Microsoft proxy endpoint
to redirect users to their Fleet instance if the
`getAccessTokenAndApiUrls` helper returns an error.
2025-11-13 10:41:47 -06:00
Eric 43337c2700 Website: Update name of value returned by Microsoft proxy endpoint (result.details » result.detail) (#34326)
Related to: https://github.com/fleetdm/fleet/issues/34306

Changes:
- Updated the `microsoft-proxy/get-one-compliance-status-result`
endpoint to send error details from failed compliance status updates as
`result.detail`.

Context:
Fleet instances expect this endpoint to return a value named `detail`
https://github.com/fleetdm/fleet/blob/94d801f9e1425e4c77334c87b2bc31f2697c5a0d/server/service/conditional_access_microsoft_proxy/conditional_access_microsoft_proxy.go#L171-L172
2025-10-15 17:29:42 -05:00
Lucas Manuel Rodriguez ee4fae8d69 Add easy to understand errors when setting up Entra conditional access (#33453)
Resolves #32420.

Demo of the changes:

https://github.com/user-attachments/assets/c5ee28ba-7f67-48bb-aa25-c934a5515de4

- [X] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [X] QA'd all new/changed functionality manually
2025-09-25 22:52:28 -03:00
Eric 6f768ba6e9 Website: Update compliance proxy admin consent webhook (#32422)
Changes:
- Updated the `receive-redirect-from-microsoft` endpoint to redirect
users to their Fleet instance if an Entra admin did not consent to the
permissions requested by Fleet's compliance partner integration.
- Fixed a bug that prevented users from being redirected to their Fleet
instance if their Entra configuration is missing a required group
- Updated the `receive-redirect-from-microsoft` endpoint to require a
`state` input
2025-08-28 12:57:09 -05:00
Eric b97f4323b8 Website: Assign compliance policies to a "Fleet conditional access" group. (#32329)
Related to: #32228

Changes:
- Updated the `receive-redirect-from-microsoft` endpoint to assign the
created compliance policy to an Entra ID group named "Fleet conditional
access"
2025-08-27 10:31:24 -05:00
Eric 61261bb8a4 Website: Microsoft proxy: Add debugging logs for Fleet's integration (#32001)
Related to: https://github.com/fleetdm/fleet/issues/31986

Changes:
- Updated Microsoft proxy endpoints to log API responses from Microsoft
when it runs for Fleet's dogfood integration.
2025-08-15 19:35:46 -05:00
Eric 86f75b614c Website: Update compliance proxy redirect exits (#30800)
Changes:
- Added a badRequest exit to the Microsoft compliance proxy's admin
consent redirect endpoint.
- Updated the Microsoft compliance proxy's admin consent redirect
endpoint to use the new exit if a request is missing either a tenant or
state value.
2025-07-11 16:26:19 -05:00
Eric 7b764152b3 Website: add /remediate and /turn-on-mdm pages for Microsoft compliance proxy (#30094)
Related to: https://github.com/fleetdm/fleet/issues/26521


Changes:
- Added two pages that will be used for the Microsoft compliance proxy
(`/microsoft-compliance-partner/turn-on-mdm` &
`/microsoft-compliance-partner/remediate`)
2025-06-18 13:34:30 -05:00
EricandLucas Rodriguez 13eeebe548 Website: Add Microsoft compliance proxy endpoints. (#27403)
Changes:
- Created a new database model: `MicrosoftComplianceTenant`. A model
that stores information about complaince tenants
- Added `/policies/is-cloud-customer`: a policy that blocks requests to
microsoft proxy endpoints if a `MS API KEY` header is missing or does
not match a new config variable
(`sails.custom.config.cloudCustomerCompliancePartnerSharedSecret`)
- Added `microsoft-proxy/create-compliance-partner-tenant`: an action
that creates a database record for a new compliance tenant and generates
an API key that is used to authenticate future requests to microsoft
proxy endpoints for an entra tenant.
- Added `microsoft-proxy/get-compliance-partner-settings`: an action
that returns information about Fleet's complaince partner entra
application and the entra tenant's admin consent status (whether or not
a tenant's entra admin has granted permissions to Fleet's compliance
partner application)
- Added `microsoft-proxy/get-tenants-admin-consent-status`: an action
that updates the admin consent status of a compliance tenant record.
- Added `microsoft-proxy/setup-compliance-partner-tenant`: an action
that provisions a compliance tenant, creates a complaince policy for
macOS devices assigns the created policy to the built-in "All users"
user group on the tenants entra instance.
- Added `microsoft-proxy/update-one-devices-compliance-status`: an
action that receives information about a device on a compliance tenant's
Fleet instance, sends that information to their Entra instance, and
returns the messsage ID returned by the asynchronus Entra API.
- Added `microsoft-proxy/get-one-compliance-status-result`: an action
that returns the result of a compliance status update from the Entra
API.
- Added `sails.helpers.microsoft-proxy.get-access-token-and-api-urls` A
helper that gets an access token for a tenant's entra instance and the
URLs of the API endpoints the microsoft proxy actions use for a tenant.
- Added `scripts/send-entra-heartbeat-requests` A script that will run
daily to keep all microsoft compliance integrations provisioned.
-

---------

Co-authored-by: Lucas Rodriguez <lucas@fleetdm.com>
2025-06-11 13:01:36 -05:00