Repository navigation
test: add CIS 1.1.3 global admin count tests - #345
Conversation
Preview EnvironmentA preview environment can be spun up on demand for this PR.
|
There was a problem hiding this comment.
Pull request overview
This PR adds an automated Rego test suite for CIS Microsoft 365 Foundations v6.0.0 control 1.1.3 (Global Administrator count), validating compliant (2–4) and non-compliant (<2, >4) scenarios plus edge cases around missing/empty global_admins data.
Changes:
- Added Rego unit tests covering compliant counts of 2, 3, and 4 Global Administrators.
- Added non-compliant tests for 0, 1, 5, and 10 Global Administrators.
- Added edge-case tests for empty/missing
global_adminsand for expected result structure fields.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
CI: Engine
All checks passed. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f4f951e5ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
akshitpatel1732
left a comment
There was a problem hiding this comment.
Hi @karansoni15-create, thanks for your contributions around this test. Could you please look into the Codex suggestion to ensure this test is actually used when necessary?
Once this issue is resolved, I'll review this PR again.
|
Hi @karansoni15-create, is this PR still being worked on? I noticed that the issue I highlighted is still awaiting resolution. In addition, this PR now includes an additional file beyond the scope of this PR. Could you please remove the unrelated file as well? Note: The code freeze for this trimester (T2 2026) is 14/09/2026. |
|
I’ve addressed the remaining PR-side issues without changing the production policy or metadata. The 1.1.3 scenarios are now in the existing compliance behavioural fixture framework, the JSON fixtures have been formatted to satisfy the repository linter, and the OPA/compliance verification is passing. A fresh review has already been requested. |
Summary
Adds CI-executed behavioural coverage for CIS Microsoft 365 Foundations v6.0.0 control 1.1.3 (Global Administrator count).
Changes
global_adminsresource list when the authoritative count is valid.CI Integration
These scenarios use the repository's existing Compliance Engine Verification Framework under
engine/tests/fixtures/compliance/. The existing Engine CI compliance-verification job runspython -m scripts.validate_engine, which executes the real Rego policy through OPA and fails CI when expected and actual compliance differ.Scope
This PR only extends behavioural verification for control 1.1.3. It does not modify the production policy, collector, metadata, permissions, or CI workflow.
Control
CIS Microsoft 365 Foundations v6.0.0
Control 1.1.3 — Ensure that between two and four global admins are designated.