Skip to content

test: add CIS 1.1.3 global admin count tests - #345

Merged
akshitpatel1732 merged 18 commits into
mainfrom
karan/1.1.3-global-admin-tests
Sep 25, 2026
Merged

akshitpatel1732 merged 18 commits into
mainfrom
karan/1.1.3-global-admin-tests

Conversation

@karansoni15-create

@karansoni15-create karansoni15-create commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds CI-executed behavioural coverage for CIS Microsoft 365 Foundations v6.0.0 control 1.1.3 (Global Administrator count).

Changes

  • Added boundary fixtures for 2 and 4 Global Administrators (compliant).
  • Added 0 and 10 Global Administrator scenarios (non-compliant).
  • Added edge cases for an empty or omitted global_admins resource list when the authoritative count is valid.
  • Removed the standalone Rego test file that was not executed by the repository CI.
  • Removed the unrelated workflow changes from this PR.

CI Integration

These scenarios use the repository's existing Compliance Engine Verification Framework under engine/tests/fixtures/compliance/. The existing Engine CI compliance-verification job runs python -m scripts.validate_engine, which executes the real Rego policy through OPA and fails CI when expected and actual compliance differ.

Scope

This PR only extends behavioural verification for control 1.1.3. It does not modify the production policy, collector, metadata, permissions, or CI workflow.

Control

CIS Microsoft 365 Foundations v6.0.0
Control 1.1.3 — Ensure that between two and four global admins are designated.

Copilot AI lite review requested due to automatic review settings August 30, 2026 04:00
@karansoni15-create
karansoni15-create requested a review from a team as a code owner August 30, 2026 04:00
@github-actions

Copy link
Copy Markdown
Contributor

Preview Environment

A preview environment can be spun up on demand for this PR.

Action Label Includes
Spin up preview deploy-preview Frontend, backend, database, Redis, OPA, worker
Spin up preview with M365 deploy-preview-m365 Everything above + PowerShell service for Exchange/Teams scan testing
Tear down preview teardown-preview Stops the environment early

The environment will also be torn down automatically when the PR is closed or merged.
Preview URLs will appear in a follow-up comment once the deploy completes (~5–8 min).
M365 scans require real tenant credentials added through the frontend UI.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR adds an automated Rego test suite for CIS Microsoft 365 Foundations v6.0.0 control 1.1.3 (Global Administrator count), validating compliant (2–4) and non-compliant (<2, >4) scenarios plus edge cases around missing/empty global_admins data.

Changes:

  • Added Rego unit tests covering compliant counts of 2, 3, and 4 Global Administrators.
  • Added non-compliant tests for 0, 1, 5, and 10 Global Administrators.
  • Added edge-case tests for empty/missing global_admins and for expected result structure fields.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

CI: Engine

Job Result
Security analysis (CodeQL) ✅ success
Lint ✅ success
Tests ✅ success
Compliance verification ✅ success

All checks passed.

@akshitpatel1732

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f4f951e5ab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread engine/tests/test_cis_1_1_3_global_admin_count.rego Outdated

@akshitpatel1732 akshitpatel1732 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @karansoni15-create, thanks for your contributions around this test. Could you please look into the Codex suggestion to ensure this test is actually used when necessary?

Once this issue is resolved, I'll review this PR again.

@github-actions github-actions Bot added the area: engine Changes under /engine label Sep 8, 2026
@github-actions github-actions Bot added github_actions GitHub Actions related area: ci-cd Changes under /.github needs-review Author (or someone else) responded since the reviewer's last comment — needs another look area: multi Touches more than one work area size/M 100-249 lines changed labels Sep 10, 2026
@akshitpatel1732

Copy link
Copy Markdown
Contributor

Hi @karansoni15-create, is this PR still being worked on?

I noticed that the issue I highlighted is still awaiting resolution. In addition, this PR now includes an additional file beyond the scope of this PR. Could you please remove the unrelated file as well?
Thanks.

Note: The code freeze for this trimester (T2 2026) is 14/09/2026.

@github-actions github-actions Bot removed the needs-review Author (or someone else) responded since the reviewer's last comment — needs another look label Sep 11, 2026
@github-actions github-actions Bot added stale 7+ days no activity since last reviewer comment needs-decision 10-14 days no activity since last reviewer comment — decide outcome and removed stale 7+ days no activity since last reviewer comment labels Sep 19, 2026
@github-actions github-actions Bot added needs-review Author (or someone else) responded since the reviewer's last comment — needs another look and removed needs-decision 10-14 days no activity since last reviewer comment — decide outcome labels Sep 23, 2026
Comment thread .github/workflows/ci.engine.yml
Comment thread .github/workflows/ci.engine.yml
Comment thread .github/workflows/ci.engine.yml
@github-actions github-actions Bot removed github_actions GitHub Actions related area: ci-cd Changes under /.github labels Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

I’ve addressed the remaining PR-side issues without changing the production policy or metadata. The 1.1.3 scenarios are now in the existing compliance behavioural fixture framework, the JSON fixtures have been formatted to satisfy the repository linter, and the OPA/compliance verification is passing. A fresh review has already been requested.

@akshitpatel1732
akshitpatel1732 merged commit 50ce66c into main Sep 25, 2026
19 of 21 checks passed
@github-actions github-actions Bot removed the needs-review Author (or someone else) responded since the reviewer's last comment — needs another look label Sep 25, 2026
@github-actions
github-actions Bot deleted the karan/1.1.3-global-admin-tests branch September 25, 2026 10:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: engine Changes under /engine area: multi Touches more than one work area size/M 100-249 lines changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants