Skip to content

Document Entity Pivot and optional Intune device inventory - #480

Merged
maximelb merged 3 commits into
masterfrom
entity/f-docs
Oct 4, 2026
Merged

maximelb merged 3 commits into
masterfrom
entity/f-docs

Conversation

@maximelb

@maximelb maximelb commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Entity Pivot helps investigators turn an email address, hostname, IP or sensor ID into User and Host identities across security products. This adds its user guide and navigation entry, including identifier types, confidence, ambiguity, permissions, readiness, history limits, API routes and rollout-dependent MCP/CLI support.

The Entra setup guide adds the optional Intune managed-device application permission, what it enables and the not_granted behavior. Existing directory collection remains available without it. The guide avoids implying that an existing setup script already grants this new permission.

Risk: documentation describes readers and clients during rollout. Publication is held until production feature enablement; and verify released CLI/MCP availability before removing the availability note. No data, configuration or runtime changes.

Validation: exact-head CI passes rendered docs, 215 Python tests, Go/Python snippet compilation and markdown/link checks. MCP prefix search is included with readiness and continuation semantics. Strict MkDocs build; rendered navigation and Entra section; complete identifier vocabulary; ordered-list, release-heading and release-feed checks. Public-content scrub passed for the diff and commit metadata. The optional application grant and tenant licence requirement were checked against Microsoft Graph's managed-device documentation. The currently installed CLI has no entity group, so no runnable new-release examples are asserted.

Live check: in an enabled organization, search an identifier, verify distinct Users/Hosts and confidence, inspect an ambiguous and a possible match, and check restricted activity statuses. Before enablement, expect missing console entry or feature_disabled. Without event permission, expect sightings forbidden and no endpoint timeline. Without Intune consent, expect optional not_granted while directory collection continues. Any automatic selection of an unconfirmed candidate, omitted forbidden source, or claimed empty result while the index is unready falsifies the guide.

🤖 Generated with Claude Code

@maximelb

maximelb commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 3, 2026
@maximelb

maximelb commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 4, 2026
@limacharlie-refractionpoint

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation 3f6b540…7868d86 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

@maximelb
maximelb merged commit eaa4ee5 into master Oct 4, 2026
7 checks passed
@maximelb
maximelb deleted the entity/f-docs branch October 4, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants