Fix authentication context ClaimValue being overwritten during policy update #1783
      
        
          +0
        
        
          −1
        
        
          
        
      
    
  
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
Fix authentication context ClaimValue being overwritten during policy update.
This PR fixes a bug where the
required_conditional_access_authentication_contextfield inazuread_group_role_management_policyresource setsclaimValuetonullinstead of the user-provided value.This bug prevented users from setting conditional access authentication contexts for PIM for Groups policies, forcing them to use workarounds with the
msgraphprovider. With this fix, users can now properly configure authentication contexts using the typedazuread_group_role_management_policyresource as intended.The Read function already correctly reads the ClaimValue, confirming this is purely an update bug and the fix is complete.
Community Note
Description
In
internal/services/policies/group_role_management_policy_resource.go, thebuildPolicyForUpdatefunction overwrites the user input with old value and hence we need to remove the linerule.ClaimValue = existingRule.ClaimValue:The pattern is clear: only copy Target from existing rule (API-controlled field that shouldn't change), never copy user-controlled data fields.
Changes to existing Resource / Data Source
Testing
Change Log
Below please provide what should go into the changelog (if anything) conforming to the Changelog Format documented here.
azuread_resource- support for thething1property [GH-00000]This is a (please select all that apply):
Related Issue(s)
Fixes #1605
Rollback Plan
If a change needs to be reverted, we will publish an updated version of the provider.
Changes to Security Controls
Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.
Note
If this PR changes meaningfully during the course of review please update the title and description as required.