Skip to content

feat(entraid): add group overage check before the STS call - #916

Merged
Gearheads merged 1 commit into
fidelity:mainfrom
Gearheads:feature/improve-group-overage-error-handling
Sep 22, 2026
Merged

Gearheads merged 1 commit into
fidelity:mainfrom
Gearheads:feature/improve-group-overage-error-handling

Conversation

@Gearheads

@Gearheads Gearheads commented Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

What this PR does / why we need it:
This change will update the entra-id protocol to check for group overage regardlless of how the role ARN was provided.

Which issue(s) this PR fixes (optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when PR gets merged):
Fixes # This should now return the same error message when a user supplies the AWS IAM role ARN through the --role-arn flag, or when a user selects the AWS IAM role through prompts.

Testing

make ci and make lint completed successfully.

Example error message that the user will see:

fatal   failed executing root command
   {"error": "authenticating using provider entraid-oauth:
   assuming role with web identity: token has a groups overage:
   user is a member of too many groups for Entra ID to include a groups claim;
   use an app role or a different group instead of relying on the groups claim,
   or reduce the user's group membership count"}

This branch can be deleted once it is merged.

This change will update the entra-id protocol to check for group overage regardlless of how the role ARN was provided. This should now return the same error message when a user supplies the AWS IAM role ARN through the --role-arn flag, or when a user selects the AWS IAM role through prompts.

Signed-off-by: Rob Casale <rcasale48@verizon.net>
@Gearheads
Gearheads merged commit 036093a into fidelity:main Sep 22, 2026
14 checks passed
@Gearheads
Gearheads deleted the feature/improve-group-overage-error-handling branch September 22, 2026 15:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant