private/Assert-MsecAdminSession.ps1

function Assert-MsecAdminSession {
    <#
    .SYNOPSIS
        Throws a clear error unless Connect-MsecAdmin has established a live write session.

    .DESCRIPTION
        The app session from Connect-Msec is not a weaker version of this one - it is the wrong
        one. New-MsecApp consents only *.Read.All, so the Key Vault certificate has no write
        permission to fall back on, and a caller who has merely run Connect-Msec needs to be
        told that rather than sent into a 403 that names no scope.

        Also re-checks Get-MgContext, because $script:MsecAdminSession records that a sign-in
        HAPPENED, not that it still holds - Disconnect-MgGraph, a token expiry or another module
        calling Connect-MgGraph all leave the variable set and the connection gone.

    .PARAMETER Scope
        Delegated scopes the caller needs. Checked against what the tenant actually granted, so
        a missing consent is named here instead of arriving as an unexplained 403 mid-write.
    #>

    [CmdletBinding()]
    param(
        [Parameter()]
        [string[]] $Scope
    )

    if (-not $script:MsecAdminSession) {
        throw ('No write session. Run Connect-MsecAdmin first. The app session from Connect-Msec cannot ' +
               'be used for this: New-MsecApp consents only *.Read.All permissions, so the certificate in ' +
               'Key Vault has no write access - writes run as you, not as the app.')
    }

    $context = Get-MgContext -ErrorAction SilentlyContinue
    if (-not $context) {
        $script:MsecAdminSession = $null
        throw ('The write session recorded by Connect-MsecAdmin is no longer connected - Disconnect-MgGraph, ' +
               'an expired token or another module reconnecting Graph will do that. Run Connect-MsecAdmin again.')
    }

    if ($Scope) {
        $granted = @($script:MsecAdminSession.GrantedScope)
        $missing = @($Scope | Where-Object { $_ -notin $granted })
        if ($missing.Count) {
            throw ("The write session as $($script:MsecAdminSession.Account) does not hold: $($missing -join ', '). " +
                   "Reconnect with: Connect-MsecAdmin -Scope $($Scope -join ',')")
        }
    }
}