en-US/about_Azure.Admin.Console.help.txt

TOPIC
    about_Azure.Admin.Console
 
SHORT DESCRIPTION
    Azure admin reports and checks from PowerShell, over plain REST, with no
    Az or Microsoft.Graph modules.
 
LONG DESCRIPTION
    Azure.Admin.Console signs you in to Azure with your browser, then reads
    your estate through Azure Resource Graph and the Azure Resource Manager
    REST API. It turns what it reads into:
 
      - a colourful Spectre.Console view at the prompt,
      - flat PowerShell objects you can filter, group and sort,
      - CSV files written with Export-Csv (one row per item, the same
        columns on every row, ready for Excel or Power BI),
      - PDF reports laid out for people who don't use PowerShell,
      - interactive HTML reports that work offline.
 
    Nothing in Azure is ever changed. Reader access to the subscriptions is
    enough for every command.
 
COMMANDS
    Connect-AAC
        Signs in with an interactive browser flow (OAuth 2.0 authorization
        code with PKCE and a localhost redirect). No app registration is
        needed: it uses the Azure CLI's public client ID, pre-consented in
        every Entra ID tenant, unless you pass -ClientId.
 
    Disconnect-AAC
        Forgets the sign-in.
 
    Get-AACAdvisorRecommendation
        A consolidated, flattened view of every Azure Advisor
        recommendation (Cost, Security, Reliability, Operational excellence,
        Performance), with estimated savings, retirement dates and
        postponed/dismissed status.
 
    Get-AACFirewallRule
        Every Azure Firewall Policy rule (DNAT, network, application) with
        IP Groups resolved, searchable by source, destination, port and
        protocol. Allow in green, Deny in red, DNAT in orange.
 
    Show-AACResource
        A colourful bar chart of your resources by type, location,
        resource group or subscription; -HtmlPath writes a full inventory.
 
    Get-AACInventory
        The tenant as a tree: management groups, subscriptions, resource
        groups and resources, with counts at every level; empty resource
        groups flagged. A console tree, objects, and CSV, PDF and
        interactive HTML reports (a searchable tree and four tables).
 
    Show-AACResourceMap
        A map of one or more resource groups, opened in your browser: the
        resources with their Azure icons in subscription, resource group,
        VNet and subnet boxes, with their connections, dependencies and
        network paths (peering, private links, routes through a firewall).
        Unattached resources are flagged. Saves as PNG or JPEG.
 
    Show-AACCost
        Subscription costs from Cost Management: month to date by
        subscription, service and resource group, and the monthly trend.
 
    Invoke-AACPSRule
        PSRule for Azure (500+ Well-Architected rules), the module's own
        rules and your custom rules on the live estate.
 
    Invoke-AACApplicationInsightQuery
        Application Insights exceptions, flattened, from a Log Analytics
        workspace or an Application Insights resource - or any KQL query.
 
    Get-Help <command> -Full shows every parameter and example.
 
GETTING STARTED
        Import-Module Azure.Admin.Console
        Connect-AAC
 
        # Advisor: the console view, then everything to CSV, PDF and HTML
        Get-AACAdvisorRecommendation
        Get-AACAdvisorRecommendation -CsvPath .\Adv.csv -PdfPath .\Adv.pdf -HtmlPath .\Adv.html
 
        # A map of two resource groups, in the browser
        Show-AACResourceMap -ResourceGroupName 'rg-hub', 'rg-spoke-app'
 
        # Firewall rules that let 10.1.2.3 reach 10.0.0.4 on UDP 53
        Get-AACFirewallRule -SourceAddress 10.1.2.3 `
            -DestinationAddress 10.0.0.4 -Port 53 -Protocol UDP
 
        # What you run, and what it costs
        Show-AACResource
        Show-AACCost
 
        # PSRule for Azure on the live estate, as an HTML report
        Invoke-AACPSRule -HtmlPath .\PSRule.html
 
        # The last 2 hours of exceptions
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-contoso-prod'
 
CONSOLE VIEW, OBJECTS AND REPORTS
    Every command decides by where it runs:
 
        at the prompt a Spectre.Console view, shown a screen at a time
                        (any key: next page, A: the rest; -NoPaging to
                        turn paging off)
        piped onward the objects, no view (| Where-Object, ...)
        -PassThru the view and the objects
        -NoDisplay the objects only (scripts, scheduled tasks)
 
    PowerShell can't tell "$r = Get-AACFirewallRule" from a plain call,
    so add -PassThru or -NoDisplay to keep the objects in a variable.
 
    -CsvPath, -PdfPath and -HtmlPath write reports. With any of them the
    console shows only the title, the progress and the files written - the
    report is in the files. Paths are relative to the current location,
    missing folders are created and existing files are overwritten.
 
    The HTML reports are single, self-contained files that work offline:
    clickable tiles and charts that filter the tables, search, filter
    drop-downs, sortable columns, grouping with subtotals, Azure portal
    links and a CSV download of the rows shown.
 
    Every command shows the same progress display: the title, then one line
    per step with a bar, a percentage and the elapsed time. Without an
    interactive terminal (CI, redirected output) each finished step is one
    plain line.
 
PSRULE FOR AZURE
    Invoke-AACPSRule runs PSRule for Azure (the PSRule.Rules.Azure module,
    installed with this one) on every resource, resource group and
    subscription you can see, or those in -SubscriptionId.
 
        Invoke-AACPSRule
        Invoke-AACPSRule -HtmlPath .\PSRule.html -FailedOnly
        Invoke-AACPSRule -Rule 'Azure.Storage.*' -ExcludeRule 'Azure.Storage.Name'
        Invoke-AACPSRule -Baseline 'Azure.Pillar.Security'
 
    Rules:
        PSRule for Azure every rule of the installed module
        Azure.Admin.Console AAC.Resource.RequiredTags,
                             AAC.ResourceGroup.RequiredTags and
                             AAC.Resource.AllowedTagValues - off until
                             configured (PSRule\Rules in the module folder)
        custom your rule files or folders, from -RulePath
 
    -Rule and -ExcludeRule take names or wildcards. -Configuration passes
    settings to the rules:
 
        Invoke-AACPSRule -Configuration @{
            AAC_REQUIRED_TAGS = @('Owner', 'CostCenter')
            AAC_ALLOWED_TAG_VALUES = @{ Environment = @('prod', 'dev') }
            AZURE_RESOURCE_ALLOWED_LOCATIONS = @('uksouth', 'ukwest')
        }
 
    The data PSRule needs is what Export-AzRuleData exports, read with the
    Connect-AAC sign-in instead of the Az modules: Resource Graph for the
    resources, then Azure Resource Manager for the child settings PSRule
    looks at. PSRule runs in a pwsh process of its own.
 
APPLICATION INSIGHTS
    Invoke-AACApplicationInsightQuery finds a Log Analytics workspace
    (-LogWorkspaceName) or Application Insights resource
    (-ApplicationInsightsName) by name and queries it through the Log
    Analytics or Application Insights query API, with a token from the
    Connect-AAC sign-in. Needs Log Analytics Reader (or Reader).
 
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod'
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' `
            -Last 1d -MinimumSeverity Error -ExceptionType '*SqlException'
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' `
            -Query 'AppRequests | summarize count() by Name'
 
    Without -Query it reads exceptions from the last -Last (default 2h),
    narrowed by -MinimumSeverity, -ExceptionType, -AppRoleName, -Search
    and -Top, flattened into one object each: time, severity, type and
    message, outer and innermost exceptions, the details array's type,
    message and severity level, the top stack frame, operation, app and
    client. With -Query each row keeps the query's columns.
 
REQUIREMENTS
    - PowerShell 7.2 or later. PDF export needs PowerShell 7.4 or later on
      Windows. Everything else works on Windows, Linux and macOS.
    - PSRule.Rules.Azure 1.47 or later. It is installed with the module.
    - A browser for Connect-AAC, and Reader access to the subscriptions.
 
SECURITY
    - The sign-in is kept only in memory for the PowerShell session. It is
      never written to disk. Disconnect-AAC forgets it.
    - No client secret is used. PKCE protects the sign-in code, and the
      redirect goes only to localhost.
    - The bundled Spectre.Console and PDFsharp/MigraDoc assemblies in lib\
      are checked against pinned SHA-256 hashes before they load. A changed
      file is refused.
 
TROUBLESHOOTING
    A command fails
        At the console, the step that was running turns red and a panel
        shows what failed, that step and what to do. The command then stops
        with its own error: try/catch, $Error and -ErrorVariable work as
        usual, and FullyQualifiedErrorId is AzureRequestFailed<status>,
        CommandFailed or InternalError. There's no panel in non-interactive
        output or with -ErrorAction SilentlyContinue. InternalError is a bug
        in the module; its message gives the file and line. Please report
        it at https://github.com/ChendrayanV/Azure.Admin.Console/issues.
 
    Symbols show as plain ASCII (*, ->, +, -)
        The console isn't UTF-8 (often code page 437 or 850), so the module
        draws its symbols in ASCII rather than letting them print as ?.
        For the full display, run
        [Console]::OutputEncoding = [Text.Encoding]::UTF8 (add it to your
        $PROFILE to keep it) and import the module again.
 
    "requires a minimum Windows PowerShell version of '7.2'"
        The module runs on PowerShell 7.2 or later (pwsh), not Windows
        PowerShell 5.1. Install it with: winget install Microsoft.PowerShell
 
    "Not connected to Azure"
        Run Connect-AAC in the same PowerShell session first.
 
    Sign-in times out
        Finish signing in within 180 seconds, or pass -TimeoutSeconds.
        Some tenants block the Azure CLI client ID. If yours does, pass your
        own App Registration's -ClientId (platform "Mobile and desktop
        applications", redirect URI http://localhost).
 
    Nothing is returned
        The account may not have Reader access on the subscriptions, or the
        filters matched nothing. Try again without -SubscriptionId or the
        other filters.
 
    PDF export fails on Linux, macOS or PowerShell 7.2 or 7.3
        PDF export needs Windows and PowerShell 7.4 or later. Use -CsvPath
        or -HtmlPath instead.
 
SEE ALSO
    Get-Help Connect-AAC -Full
    Get-Help Get-AACAdvisorRecommendation -Full
    Get-Help Get-AACFirewallRule -Full
    Get-Help Invoke-AACPSRule -Full
    Get-Help Invoke-AACApplicationInsightQuery -Full
    https://azure.github.io/PSRule.Rules.Azure/
    https://learn.microsoft.com/azure/governance/resource-graph/