Skip to main content

AAD Group - Read member summary using CSharp

 Is there a way to read Azure Active directory Group (Service or Microsoft 365) programmatically 

There are different ways to do it one of them is using AAD App 

let's see with the following example: 


Pre-requisite:

  • Create an AAD App 
    • Get the AAD Group Member Reader & User Read All permission through Microsoft Graph (application permission) 
    • Create a client secret (we'll use this to access your AAD Group information in the context of AAD App)
  • Create a CSharp project (detail mentioned below)



Create and AAD App with AAD GroupMember read & user read all permission

 Step-1: Create an aad app: Login to azure porta => Azure Active Directory => App registration => create new app 

 Step-2. Once AAD App is created (e.g.: AADGroupReader) 

      Open it. 

  Go to it's API Permissions



  Click on Add Permission

  From right-hand side select "Microsoft Graph"



  Now you've to search with Keywork "User"  and select "User.Read.All"



And also search for keyword "Group" and select "GroupMember.ReadWrite.All"


 

      Once you've selected both, click "Add permission" 

  Now on the API permission, you can see both "User.Read.All" & "GroupMember.Read.All" got added.



    But you will notice that status is "Not granted for default...."

If you're AAD Admin you can Grant admin consent.

If you're not AAD Admin you may have to contact your admin to grant admin consent. 

     if you are the AAD admin, you can grant the consent like this. 

Click on "Grant admin consent for default directory"  And click "Yes" from the pop-up like this.   

Once admin consent granted, you can see a status bar with Green check-mark. 



Now let's create the client secret and save the created client secrete in a safe place (e.g.: Key vault).  

Click on "Certificates & secretes" 



New client secret


Copy the client secret and save it at a safe place.



  

With this, we're good with accessing our AAD Group and it's user detail using AAD App context (SPN context). 



Now use CSharp and get the AAD group member detail with the help of created AAD App

Step-1: Open visual studio 
Step-2: Create a console app 
Step-3: Install these libraries through Nuget package 
 Install these 3 libraries using NuGet package manager
    • Microsoft.Graph;
    • Microsoft.Graph.Auth;  // at this time it's in Preview mode.
    • Microsoft.Identity.Client;

Step-4: Write a AADGroupReader class like this. 
 In this code snipped   replace your ClientId, TenantId & clientSecret of your own app & group. 
Step-5. Assume that we've an AAD Group with the name "testaddgroup" having one user with the name "Test User"

Code snipped to read the AAD Group & fetch the user summary

Utility method:
public List GetGroupMembers(string groupName)
        {
            var userList = new List();
            try
            {
                var clientId = "your-aad-app-client-id";
                var tenantId = "your-tenant-id";
                var secret = "your-aad-app-client-secret";
                IConfidentialClientApplication confidentialClientApplication = ConfidentialClientApplicationBuilder
                                                                                   .Create(clientId)
                                                                                   .WithTenantId(tenantId)
                                                                                   .WithClientSecret(secret)
                                                                                   .Build();

                IAuthenticationProvider authProvider = new ClientCredentialProvider(confidentialClientApplication);
                GraphServiceClient graphClient = new GraphServiceClient(authProvider);

                var groupsDetails = graphClient.Groups.Request()
                    .Filter($"startswith(displayName,'{groupName}')")
                    .GetAsync()
                     .ConfigureAwait(false)
                       .GetAwaiter()
                       .GetResult()
                       .ToList()
                       .Where(x => string.Equals(x.DisplayName, groupName, StringComparison.InvariantCultureIgnoreCase))
                       .FirstOrDefault();


                var groupObjectId = groupsDetails.Id;
                var groupMembers = graphClient.Groups[groupObjectId]
                       .TransitiveMembers
                       //.Members  // just to get the direct memb er
                       .Request()
                       .GetAsync()
                       .ConfigureAwait(false)
                       .GetAwaiter()
                       .GetResult();


                foreach (var mem in groupMembers.ToList())
                {
                    //var memType = mem.GetType();
                    if (mem.GetType() == typeof(User))
                    {
                        var myUser = graphClient.Users[mem.Id].Request().GetAsync()
                       .ConfigureAwait(false)
                       .GetAwaiter()
                       .GetResult();

                        User forUser = (User)mem;

                        userList.Add(new AadGroupMember
                        {
                            ObjectId = forUser.Id,
                            UserPrincipalName = forUser.UserPrincipalName,
                            Name = forUser.DisplayName,
                            Email = forUser.Mail,

                        });
                    }
                }

                return userList;
            }
            catch (Exception ex)
            {
                throw;
            }
        }
  

Heping entity:
    public class AadGroupMember
    {
        public string ObjectId { get; set; }
        public string Name { get; set; }
        public string UserPrincipalName { get; set; }
        public string Email { get; set; } //UserPrincipalName
    }
  

Working code can be found on GitHub "AzureActiveDirectory" repo. 

Comments

Popular posts from this blog

EFCore - Collate function

Search in SQL server query is generally case insensitive (by default or based on database level collation). Suppose we have an employees table with a row having first-name column value as "My-First-Name", so if we want to do the case-sensitive search we have to explicitly use the related collate: In EF 5 (currently in Release Candidate version [RC.2.20475.6]) Collate function got introduced which helps us to use our specific collation based search.  C# with EF5 code sample: var employeeCaseSensitiveSearch = _dbContext.Employees .Where(x => EF.Functions.Collate(x.FirstName, "Latin1_General_CS_AS") == "my-first-name") .FirstOrDefault(); A related database query will be something like this: T-SQL: Case sensitive search (use specific collation e.g.: Latin1_General_CS_AS) SELECT * FROM dbo.Employees AS e WHERE e.FirstName Collate Latin1_General_CS_AS = 'my-first-name' Some of the useful CSharp function which g...

Git - Update submodule

Sometimes in the large project when we separate it in different repositories we need to take reference of one repository in another where some the sub-module concepts. Now if we move our submodule to a different repository or renaming its repo-path then we've to also update the repository where this sub-module is getting referenced. Let's see how to update the git submodule.  Step-1: First clone the repo Step-2: Open git UI to create a new local branch from master  Step-3: Open git bash -- Now run below command to (remove submodules & add them):  -- Remove submodule git submodule deinit YOUR_FIRST_REPO git rm YOUR_FIRST_REPO git commit -m "Removed submodule YOUR_FIRST_REPO" rm -rf .git/modules/YOUR_FIRST_REPO -- Add submodule git submodule add <<..YOUR_FIRST_REPO git URL>> Step-4: All good, let's push our changes to the master

EFCore - Update command is not updating the underlying data

Why my update command using EFCore is not updating the underlying data in the database though in middle-tier code it's successful, not throwing any error? Let's try to get the root cause and how to solve this.  When creating the model class of related database object if the primary key name is Id then no need to explicitly mention the Key in ef-core OnModelCreating.  But if we've key name different from Id then we have to explicitly mention it in our OnModelCreating. Something like this:  entity.HasKey(c => new {c.CustId }); Assume in the database we've Customers table like this: CREATE TABLE [dbo].[Customers]( [CustId] [INT] IDENTITY(1,1) NOT NULL Primary Key, [FirstName] [VARCHAR](50) NULL ) Point to ponder: In the database table, column CustId is already defined as Primary key.  In EFCore model setup, it's up to us to configure the Key as (custId) or configure it as HasNoKey() Assume we've set our entity with Ha...