Skip to content

Live Demo State

croesus-agent edited this page Jul 7, 2026 · 1 revision

Live demo state

This page is a durable record of the three live objects the Tier 2 demo provisions in the demo tenant (MngEnvMCAP675646.onmicrosoft.com, aa93b9d9-037d-4f08-a26d-783cff0e2369). Capture it before any teardown so the exact live state is preserved. Every object here is reversible with the scripts listed at the end.

Captured 2026-07-06 while signed in as admin@MngEnvMCAP675646.onmicrosoft.com.

Summary of live objects

Object Identifier Live value Reverses with
Replay gate (App Service setting) Demo__EnableReplay on croesus-api true teardown-app-registrations.sh (resets to false)
Conditional Access policy 9c213f84-601b-4fb9-8366-a3828d9e4ede report-only, enabled teardown-ca-policy.sh
SPA to Graph delegated grant oauth2PermissionGrant kMoYHyDjs0GSyifXhf5Q6OrnkKCBIgVMnFXPmDBqesU User.Read granted teardown-app-registrations.sh (revokes grant)

The provisioning state file .demo-state.json (git-ignored, local to the operator) records the grant id and policy id that the teardown scripts read:

{
  "spaGraphGrant": "kMoYHyDjs0GSyifXhf5Q6OrnkKCBIgVMnFXPmDBqesU",
  "caPolicyId": "9c213f84-601b-4fb9-8366-a3828d9e4ede"
}

1. Replay gate (App Service setting)

The gated Tier 2 replay endpoint (POST /api/replay) is mapped only when this setting is true. Captured live via ARM:

[
  {
    "name": "Demo__EnableReplay",
    "slotSetting": false,
    "value": "true"
  }
]

Reproduce: az webapp config appsettings list -g rg-croesus -n croesus-api --query "[?name=='Demo__EnableReplay']" -o json.

2. Conditional Access Token Protection policy

The report-only policy that surfaces the Token Protection evaluation into the sign-in logs.

  • displayName: croesus-demo-token-protection
  • id: 9c213f84-601b-4fb9-8366-a3828d9e4ede
  • state: enabledForReportingButNotEnforced (report-only, does not block)
  • sessionControls.secureSignInSession.isEnabled: true (Require token protection for sign-in sessions)
  • conditions.clientAppTypes: ["mobileAppsAndDesktopClients"]
  • conditions.platforms.includePlatforms: ["windows", "macOS", "iOS"]
  • conditions.applications.includeApplications: ["00000002-0000-0ff1-ce00-000000000000"] (Office 365 Exchange Online)
  • conditions.users.includeUsers: ["54119dd2-572f-4f40-ac16-0c6fb419f24f"] (single scoped test user)
  • conditions.users.excludeUsers: ["b785230a-4af4-418a-acd9-aea99894d37a"] (break-glass exclusion)

The authoritative definition lives in scripts/provision-ca-policy.sh. Portal confirmation:

Conditional Access policy croesus-demo-token-protection in the Entra admin center

Reproduce the JSON (requires an interactive Graph token): az rest --method GET --uri "https://graph.microsoft.com/beta/identity/conditionalAccess/policies/9c213f84-601b-4fb9-8366-a3828d9e4ede".

3. SPA to Microsoft Graph delegated grant

To let the SPA acquire a real Graph token and forward it to POST /api/replay, the demo adds a delegated User.Read grant for the SPA against Microsoft Graph (oauth2PermissionGrant id kMoYHyDjs0GSyifXhf5Q6OrnkKCBIgVMnFXPmDBqesU). Portal confirmation of the SPA app permissions:

Croesus SPA (mock) API permissions in the Entra admin center

  • SPA application: Croesus GPD Central SPA (mock), appId 06ef7c0a-9df3-4bcd-8b6f-ee275ca0adc2
  • API resource: Croesus GPD Central API (mock), appId bc6338a5-a02a-4ddf-b1f4-9a9234bed8a8, delegated scope access_as_user
  • Added grant: Microsoft Graph User.Read (delegated)

Reversible teardown

Every object above reverses cleanly. Run from the repository root:

Preserve .demo-state.json until teardown: the scripts read the grant id and policy id from it.

Clone this wiki locally