Skip to content

Add SharePoint Online expand_site_group_members RCF - #288070

Merged
Jan-Kazlouski-elastic merged 3 commits into
elastic:mainfrom
Jan-Kazlouski-elastic:jan-kazlouski/sharepoint-expand-site-group-members-rcf
Sep 18, 2026
Merged

Jan-Kazlouski-elastic merged 3 commits into
elastic:mainfrom
Jan-Kazlouski-elastic:jan-kazlouski/sharepoint-expand-site-group-members-rcf

Conversation

@Jan-Kazlouski-elastic

@Jan-Kazlouski-elastic Jan-Kazlouski-elastic commented Aug 31, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Adds the expand_site_group_members rich configurable field for the SharePoint Online native connector so Fleet shows the compact site-group DLS toggle.

Related connectors PR: elastic/connectors#4396

Checklist

  • Any text added follows EUI's writing guidelines, uses sentence case text and includes i18n support
  • Documentation was added for features that require explanation or tutorials
  • Unit or functional tests were updated or added to match the most common scenarios
  • If a plugin configuration key changed, check if it needs to be allowlisted in the cloud and added to the docker list
  • This was checked for breaking HTTP API changes, and any breaking changes have been approved by the breaking-change committee. The release_note:breaking label should be applied in these situations.
  • Flaky Test Runner was used on any tests changed
  • The PR description includes the appropriate Release Notes section, and the correct release_note:* label is applied per the guidelines
  • Review the backport guidelines and apply applicable backport:* labels.

Identify risks

  • See some risk examples
  • Low risk. This only exposes an existing connector configuration field in Fleet. No runtime behavior changes in Kibana.

Release note

SharePoint Online connectors now expose an Expand site group members toggle in Fleet for compact document-level security.

Expose the compact site-group DLS toggle in Fleet so it matches the
connectors SharePoint Online configuration schema.

@jgowdyelastic jgowdyelastic left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Jan-Kazlouski-elastic

Copy link
Copy Markdown
Collaborator Author

@elasticmachine merge upstream

Jan-Kazlouski-elastic added a commit to elastic/connectors that referenced this pull request Sep 18, 2026
…#4396)

## Closes elastic/chat-program#48

Part of elastic/chat-program#47.
SharePoint Online DLS expands every site group member onto each
document's `_allow_access_control` array. Large site groups can produce
multi-megabyte ACLs per document and OOM Elasticsearch during
`_reindex`.

This PR adds `expand_site_group_members` (default `true` to preserve
existing behavior). When disabled (compact mode):

- Content documents store a compact `site_group:<site_id>:<group_id>`
token instead of every site group member
- Direct user, Entra group, and site user permissions are unchanged on
the document
- ACL sync builds a site-group membership index and enriches identity
docs so DLS term overlap still resolves access (including nested Entra
groups and EEEU guest exclusion)
- If a compact token cannot be written safely (e.g. missing `site_id`),
the connector falls back to expanding site group members and logs a
warning

Changing the setting requires a full content sync and access control
sync.

## Checklists

#### Pre-Review Checklist
- [x] this PR does NOT contain credentials of any kind, such as API keys
or username/passwords (double check `config.yml.example`)
- [x] this PR has a meaningful title
- [x] this PR links to all relevant github issues that it fixes or
partially addresses
- [x] if there is no GH issue, please create it. Each PR should have a
link to an issue
- [x] this PR has a thorough description
- [x] Covered the changes with automated tests
- [x] Tested the changes locally
- [ ] Added a label for each target release version (example: `v7.13.2`,
`v7.14.0`, `v8.0.0`)
- [ ] For bugfixes: backport safely to all minor branches still
receiving patch releases
- [ ] Considered corresponding documentation changes
- [ ] Contributed any configuration settings changes to the
configuration reference
- [x] if you added or changed Rich Configurable Fields for a Native
Connector, you made a corresponding PR in
[Kibana](https://github.com/elastic/kibana/blob/main/packages/kbn-search-connectors/types/native_connectors.ts)

#### Changes Requiring Extra Attention

- [x] Security-related changes (encryption, TLS, SSRF, etc)
- [ ] New external service dependencies added.

## Related Pull Requests

* #4392 — ServiceNow compact
role DLS (same tracking issue)
* elastic/kibana#288070 — Kibana RCF for
`expand_site_group_members`

## Release Note

SharePoint Online document-level security can store compact site-group
tokens on documents instead of expanding every site group member onto
each record, reducing memory use for large site groups. Disable **Expand
site group members** to enable compact mode. The default preserves the
previous behavior. Changing the setting requires a full content sync and
access control sync.

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
Jan-Kazlouski-elastic added a commit to elastic/connectors that referenced this pull request Sep 18, 2026
… memory (#4396) (#4501)

Backported from #4396

Part of elastic/chat-program#47.

Auto-backport to `8.19` failed with cherry-pick conflicts because this
branch still uses the monolithic
`connectors/sources/sharepoint_online.py` layout (not the
`sharepoint/sharepoint_online/` package on `main`). Changes were
manually adapted from #4396; behaviour matches the merged main PR.

Adds `expand_site_group_members` (default `true`) for compact site-group
DLS tokens on documents, ACL-sync membership indexing, and identity
enrichment when compact mode is enabled.

## Backport notes

- Single-file port: `connectors/sources/sharepoint_online.py` (client +
datasource + helpers).
- Tests and fixture updated under `tests/sources/`.
- Kibana RCF for `expand_site_group_members`:
elastic/kibana#288070 (unchanged from main).

## Test plan

- [ ] CI green
- [ ] `pytest tests/sources/test_sharepoint_online.py -k "site_group or
guest_user or compact"`

## Release Note

SharePoint Online document-level security can store compact site-group
tokens on documents instead of expanding every site group member onto
each record, reducing memory use for large site groups. Disable **Expand
site group members** to enable compact mode. The default preserves the
previous behavior. Changing the setting requires a full content sync and
access control sync.
@kibanamachine

Copy link
Copy Markdown
Contributor

💛 Build succeeded, but was flaky

Failed CI Steps

Metrics [docs]

Page load bundle

Size of the bundles that are downloaded on every page load. Target size is below 100kb

id before after diff
shared-packages 4.7MB 4.7MB +824.0B
Unknown metric groups

total optimizer output size

id before after diff
all 64.3MB 64.3MB +824.0B

warm start memory

id before after diff
post forced gc heap baseline - 855173324 +855173324
post forced gc heap delta - -2508518 -2508518
post forced gc heap delta standard deviation - 2137494 +2137494
post forced gc heap target - 852664806 +852664806
tail heap delta - -39307696 -39307696
total +1668159410

Test Failures

  • [job] [logs] FTR Configs #31 / Serverless Common UI - Management Data View Management runtime fields create runtime field should delete runtime field
  • [job] [logs] FTR Configs #31 / Serverless Common UI - Management Data View Management runtime fields create runtime field should modify runtime field
  • [job] [logs] FTR Configs #31 / Serverless Common UI - Management Data View Management runtime fields create runtime field verify field format

History

cc @Jan-Kazlouski-elastic

@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic added this pull request to the merge queue Sep 18, 2026
Merged via the queue into elastic:main with commit ef066d3 Sep 18, 2026
130 checks passed
@Jan-Kazlouski-elastic
Jan-Kazlouski-elastic deleted the jan-kazlouski/sharepoint-expand-site-group-members-rcf branch September 18, 2026 16:04
@kibanamachine

Copy link
Copy Markdown
Contributor

Starting backport for target branches: 8.19, 9.4, 9.5

https://github.com/elastic/kibana/actions/runs/35366250327

@kibanamachine

Copy link
Copy Markdown
Contributor

💚 All backports created successfully

Status Branch Result
✅ 8.19
✅ 9.4
✅ 9.5

Note: Successful backport PRs will be merged automatically after passing CI.

Questions ?

Please refer to the Backport tool documentation

kibanamachine added a commit that referenced this pull request Sep 18, 2026
…292092)

# Backport

This will backport the following commits from `main` to `9.4`:
- [Add SharePoint Online expand_site_group_members RCF
(#288070)](#288070)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT
[{"author":{"name":"Jan-Kazlouski-elastic","email":"jan.kazlouski@elastic.co"},"sourceCommit":{"committedDate":"2026-09-18T13:38:28Z","message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95","branchLabelMapping":{"^v9.6.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Search","backport:version","v9.6.0","v9.5.5","v9.4.8","v8.19.23"],"title":"Add
SharePoint Online expand_site_group_members
RCF","number":288070,"url":"https://github.com/elastic/kibana/pull/288070","mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},"sourceBranch":"main","suggestedTargetBranches":["9.5","9.4","8.19"],"targetPullRequestStates":[{"branch":"main","label":"v9.6.0","branchLabelMappingKey":"^v9.6.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/288070","number":288070,"mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},{"branch":"9.5","label":"v9.5.5","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"9.4","label":"v9.4.8","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"8.19","label":"v8.19.23","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
kibanamachine added a commit that referenced this pull request Sep 18, 2026
…292093)

# Backport

This will backport the following commits from `main` to `9.5`:
- [Add SharePoint Online expand_site_group_members RCF
(#288070)](#288070)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT
[{"author":{"name":"Jan-Kazlouski-elastic","email":"jan.kazlouski@elastic.co"},"sourceCommit":{"committedDate":"2026-09-18T13:38:28Z","message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95","branchLabelMapping":{"^v9.6.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Search","backport:version","v9.6.0","v9.5.5","v9.4.8","v8.19.23"],"title":"Add
SharePoint Online expand_site_group_members
RCF","number":288070,"url":"https://github.com/elastic/kibana/pull/288070","mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},"sourceBranch":"main","suggestedTargetBranches":["9.5","9.4","8.19"],"targetPullRequestStates":[{"branch":"main","label":"v9.6.0","branchLabelMappingKey":"^v9.6.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/288070","number":288070,"mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},{"branch":"9.5","label":"v9.5.5","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"9.4","label":"v9.4.8","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"8.19","label":"v8.19.23","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
kibanamachine added a commit that referenced this pull request Sep 18, 2026
…292091)

# Backport

This will backport the following commits from `main` to `8.19`:
- [Add SharePoint Online expand_site_group_members RCF
(#288070)](#288070)

<!--- Backport version: 9.6.6 -->

### Questions ?
Please refer to the [Backport tool
documentation](https://github.com/sorenlouv/backport)

<!--BACKPORT
[{"author":{"name":"Jan-Kazlouski-elastic","email":"jan.kazlouski@elastic.co"},"sourceCommit":{"committedDate":"2026-09-18T13:38:28Z","message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95","branchLabelMapping":{"^v9.6.0$":"main","^v(\\d+).(\\d+).\\d+$":"$1.$2"}},"sourcePullRequest":{"labels":["release_note:fix","Team:Search","backport:version","v9.6.0","v9.5.5","v9.4.8","v8.19.23"],"title":"Add
SharePoint Online expand_site_group_members
RCF","number":288070,"url":"https://github.com/elastic/kibana/pull/288070","mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},"sourceBranch":"main","suggestedTargetBranches":["9.5","9.4","8.19"],"targetPullRequestStates":[{"branch":"main","label":"v9.6.0","branchLabelMappingKey":"^v9.6.0$","isSourceBranch":true,"state":"MERGED","url":"https://github.com/elastic/kibana/pull/288070","number":288070,"mergeCommit":{"message":"Add
SharePoint Online expand_site_group_members RCF (#288070)\n\n##
Summary\n\nAdds the `expand_site_group_members` rich configurable field
for the\nSharePoint Online native connector so Fleet shows the compact
site-group\nDLS toggle.\n\nRelated connectors PR:
https://github.com/elastic/connectors/pull/4396\n\n### Checklist\n\n-
[x] Any text added follows [EUI's
writing\nguidelines](https://elastic.github.io/eui/#/guidelines/writing),
uses\nsentence case text and includes
[i18n\nsupport](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)\n-
[
]\n[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)\nwas
added for features that require explanation or tutorials\n- [ ] [Unit or
functional\ntests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)\nwere
updated or added to match the most common scenarios\n- [ ] If a plugin
configuration key changed, check if it needs to be\nallowlisted in the
cloud and added to the
[docker\nlist](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)\n-
[ ] This was checked for breaking HTTP API changes, and any
breaking\nchanges have been approved by the breaking-change committee.
The\n`release_note:breaking` label should be applied in these
situations.\n- [ ] [Flaky
Test\nRunner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1)
was\nused on any tests changed\n- [x] The PR description includes the
appropriate Release Notes section,\nand the correct `release_note:*`
label is applied per
the\n[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)\n-
[ ] Review the
[backport\nguidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)\nand
apply applicable `backport:*` labels.\n\n### Identify risks\n\n- [ ]
[See some
risk\nexamples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)\n-
[x] Low risk. This only exposes an existing connector
configuration\nfield in Fleet. No runtime behavior changes in
Kibana.\n\n## Release note\n\nSharePoint Online connectors now expose an
**Expand site group members**\ntoggle in Fleet for compact
document-level security.\n\nCo-authored-by: Elastic Machine
<elasticmachine@users.noreply.github.com>","sha":"ef066d343d569f1b1ff4c1dfd98fc265bdd07e95"}},{"branch":"9.5","label":"v9.5.5","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"9.4","label":"v9.4.8","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"},{"branch":"8.19","label":"v8.19.23","branchLabelMappingKey":"^v(\\d+).(\\d+).\\d+$","isSourceBranch":false,"state":"NOT_CREATED"}]}]
BACKPORT-->

Co-authored-by: Jan-Kazlouski-elastic <jan.kazlouski@elastic.co>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
ppisljar pushed a commit to ppisljar/kibana that referenced this pull request Sep 21, 2026
## Summary

Adds the `expand_site_group_members` rich configurable field for the
SharePoint Online native connector so Fleet shows the compact site-group
DLS toggle.

Related connectors PR: elastic/connectors#4396

### Checklist

- [x] Any text added follows [EUI's writing
guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses
sentence case text and includes [i18n
support](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)
- [ ]
[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)
was added for features that require explanation or tutorials
- [ ] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [ ] If a plugin configuration key changed, check if it needs to be
allowlisted in the cloud and added to the [docker
list](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)
- [ ] This was checked for breaking HTTP API changes, and any breaking
changes have been approved by the breaking-change committee. The
`release_note:breaking` label should be applied in these situations.
- [ ] [Flaky Test
Runner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was
used on any tests changed
- [x] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [ ] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.

### Identify risks

- [ ] [See some risk
examples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)
- [x] Low risk. This only exposes an existing connector configuration
field in Fleet. No runtime behavior changes in Kibana.

## Release note

SharePoint Online connectors now expose an **Expand site group members**
toggle in Fleet for compact document-level security.

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
florent-leborgne added a commit that referenced this pull request Sep 23, 2026
## Summary

Adds the Kibana 8.19.22 release notes and moves four fixes that were
listed in 8.19.21 but did not ship in that build candidate.

- Curates the 8.19.22 notes as Fixes only, including Observability
bullets and a Security pointer.
- Matches 9.x wording where those PRs already have published notes.
- Moves `#287643`, `#286703`, `#285153`, and `#282347` from 8.19.21 into
8.19.22.
- Defers `#288070` and `#291142` until they land in a later 8.19.22
build candidate.

Closes elastic/docs-content#8447

Docs release: elastic/dev#3627

## Test plan

- [ ] Confirm 8.19.22 TOC and Fixes sections render in the AsciiDoc
preview
- [ ] Confirm the four moved PRs no longer appear under 8.19.21
- [ ] Confirm deferred `#288070` and `#291142` stay commented until the
next BC


Made with [Cursor](https://cursor.com)

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
elk-rakeshjalla pushed a commit to elk-rakeshjalla/kibana that referenced this pull request Oct 5, 2026
## Summary

Adds the `expand_site_group_members` rich configurable field for the
SharePoint Online native connector so Fleet shows the compact site-group
DLS toggle.

Related connectors PR: elastic/connectors#4396

### Checklist

- [x] Any text added follows [EUI's writing
guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses
sentence case text and includes [i18n
support](https://github.com/elastic/kibana/blob/main/src/platform/packages/shared/kbn-i18n/README.md)
- [ ]
[Documentation](https://www.elastic.co/guide/en/kibana/master/development-documentation.html)
was added for features that require explanation or tutorials
- [ ] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios
- [ ] If a plugin configuration key changed, check if it needs to be
allowlisted in the cloud and added to the [docker
list](https://github.com/elastic/kibana/blob/main/src/dev/build/tasks/os_packages/docker_generator/resources/base/bin/kibana-docker)
- [ ] This was checked for breaking HTTP API changes, and any breaking
changes have been approved by the breaking-change committee. The
`release_note:breaking` label should be applied in these situations.
- [ ] [Flaky Test
Runner](https://ci-stats.kibana.dev/trigger_flaky_test_runner/1) was
used on any tests changed
- [x] The PR description includes the appropriate Release Notes section,
and the correct `release_note:*` label is applied per the
[guidelines](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- [ ] Review the [backport
guidelines](https://docs.google.com/document/d/1VyN5k91e5OVumlc0Gb9RPa3h1ewuPE705nRtioPiTvY/edit?usp=sharing)
and apply applicable `backport:*` labels.

### Identify risks

- [ ] [See some risk
examples](https://github.com/elastic/kibana/blob/main/RISK_MATRIX.mdx)
- [x] Low risk. This only exposes an existing connector configuration
field in Fleet. No runtime behavior changes in Kibana.

## Release note

SharePoint Online connectors now expose an **Expand site group members**
toggle in Fleet for compact document-level security.

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
florent-leborgne added a commit that referenced this pull request Oct 6, 2026
## Summary

Adds the Kibana 8.19.23 release notes, curated against build candidate
`8.19.23-20398209` (Kibana commit
`bb0fffbaf841ec1d529c098d5d10ff9b43f976ff`).

- Curates the 8.19.23 notes as Fixes only, including an Observability
bullet and a Security pointer.
- Matches the 9.4.8 and 9.5.5 wording for shared PRs.
- Moves `#288070` and `#291142`, deferred in 8.19.22, into 8.19.23 and
deletes their comments from 8.19.22.
- Adds `#291396`, `#291972`, `#292297`, and `#293176`, which are in this
BC but were missing from the generator dump.
- Adds `#290815` under Observability. Its backport shipped unlisted in
8.19.22 with a link to a missing page, and `#292214` fixes the link in
this BC.
- Defers `#290859` because its 8.19 backport failed with merge
conflicts.

Closes elastic/docs-content#8623

Docs release: elastic/dev#3636

## Test plan

- [ ] Confirm 8.19.23 TOC and Fixes sections render in the AsciiDoc
preview
- [ ] Confirm `#288070` and `#291142` no longer appear as comments under
8.19.22
- [ ] Confirm deferred `#290859` stays commented until the next BC

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants