diff --git a/Control coverage/Feature/SubscriptionCore.md b/Control coverage/Feature/SubscriptionCore.md index 0e7d1c55..6a46d507 100644 --- a/Control coverage/Feature/SubscriptionCore.md +++ b/Control coverage/Feature/SubscriptionCore.md @@ -71,7 +71,7 @@ Deprecated accounts are ones that were once deployed to your subscription for so ### Azure Policies or REST APIs used for evaluation -- Microsoft Defender for Cloud Recommendation - [Deprecated accounts should be removed from subscriptions](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/00c6d40b-e990-6acf-d4f3-471e747a27c4) +- Microsoft Defender for Cloud Recommendation - [Deprecated accounts should be removed from subscriptions](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/1ff0b4c9-ed56-4de6-be9c-d7ab39645926) - REST API to list role assignment at scope: - /{scope}/providers/Microsoft.Authorization/roleAssignments?api-version=2018-01-01-preview
**Properties:** [\*].properties.principalId diff --git a/Scripts/RemediationScripts/Remediate-InvalidAADObjectRoleAssignments.ps1 b/Scripts/RemediationScripts/Remediate-InvalidAADObjectRoleAssignments.ps1 index 463f5d62..2a3b29f2 100644 --- a/Scripts/RemediationScripts/Remediate-InvalidAADObjectRoleAssignments.ps1 +++ b/Scripts/RemediationScripts/Remediate-InvalidAADObjectRoleAssignments.ps1 @@ -252,7 +252,7 @@ function Remove-AzTSInvalidAADAccounts $currentRoleAssignmentList | select -Unique -Property 'ObjectId' | ForEach-Object { $distinctObjectIds += $_.ObjectId } # Getting MDC reported deprecated account object ids. - $mdcUri = "https://management.azure.com/subscriptions/$($subscriptionId)/providers/Microsoft.Security/assessments/00c6d40b-e990-6acf-d4f3-471e747a27c4?api-version=2020-01-01" + $mdcUri = "https://management.azure.com/subscriptions/$($subscriptionId)/providers/Microsoft.Security/assessments/1ff0b4c9-ed56-4de6-be9c-d7ab39645926?api-version=2020-01-01" $method = [Microsoft.PowerShell.Commands.WebRequestMethod]::Get $classicAssignments = [ClassicRoleAssignments]::new() $headers = $classicAssignments.GetAuthHeader()