en-US/about_Azure.Admin.Console.help.txt
|
TOPIC
about_Azure.Admin.Console SHORT DESCRIPTION Azure admin reports and checks from PowerShell, over plain REST, with no Az or Microsoft.Graph modules. LONG DESCRIPTION Azure.Admin.Console signs you in to Azure with your browser, then reads your estate through Azure Resource Graph and the Azure Resource Manager REST API. It turns what it reads into: - a colourful Spectre.Console view at the prompt, - flat PowerShell objects you can filter, group and sort, - CSV files written with Export-Csv (one row per item, the same columns on every row, ready for Excel or Power BI), - PDF reports laid out for people who don't use PowerShell, - interactive HTML reports that work offline. Nothing in Azure is ever changed. Reader access to the subscriptions is enough for every command. COMMANDS Connect-AAC Signs in with an interactive browser flow (OAuth 2.0 authorization code with PKCE and a localhost redirect). No app registration is needed: it uses the Azure CLI's public client ID, pre-consented in every Entra ID tenant, unless you pass -ClientId. Disconnect-AAC Forgets the sign-in. Get-AACAdvisorRecommendation A consolidated, flattened view of every Azure Advisor recommendation (Cost, Security, Reliability, Operational excellence, Performance), with estimated savings, retirement dates and postponed/dismissed status. Get-AACFirewallRule Every Azure Firewall Policy rule (DNAT, network, application) with IP Groups resolved, searchable by source, destination, port and protocol. Allow in green, Deny in red, DNAT in orange. Show-AACResource A colourful bar chart of your resources by type, location, resource group or subscription; -HtmlPath writes a full inventory. Get-AACInventory The tenant as a tree: management groups, subscriptions, resource groups and resources, with counts at every level; empty resource groups flagged. A console tree, objects, and CSV, PDF and interactive HTML reports (a searchable tree and four tables). Show-AACResourceMap A map of one or more resource groups, opened in your browser: the resources with their Azure icons in subscription, resource group, VNet and subnet boxes, with their connections, dependencies and network paths (peering, private links, routes through a firewall). Unattached resources are flagged. Saves as PNG or JPEG. Show-AACCost Subscription costs from Cost Management: month to date by subscription, service and resource group, and the monthly trend. Invoke-AACPSRule PSRule for Azure (500+ Well-Architected rules), the module's own rules and your custom rules on the live estate. Invoke-AACApplicationInsightQuery Application Insights exceptions, flattened, from a Log Analytics workspace or an Application Insights resource - or any KQL query. Get-Help <command> -Full shows every parameter and example. GETTING STARTED Import-Module Azure.Admin.Console Connect-AAC # Advisor: the console view, then everything to CSV, PDF and HTML Get-AACAdvisorRecommendation Get-AACAdvisorRecommendation -CsvPath .\Adv.csv -PdfPath .\Adv.pdf -HtmlPath .\Adv.html # A map of two resource groups, in the browser Show-AACResourceMap -ResourceGroupName 'rg-hub', 'rg-spoke-app' # Firewall rules that let 10.1.2.3 reach 10.0.0.4 on UDP 53 Get-AACFirewallRule -SourceAddress 10.1.2.3 ` -DestinationAddress 10.0.0.4 -Port 53 -Protocol UDP # What you run, and what it costs Show-AACResource Show-AACCost # PSRule for Azure on the live estate, as an HTML report Invoke-AACPSRule -HtmlPath .\PSRule.html # The last 2 hours of exceptions Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-contoso-prod' CONSOLE VIEW, OBJECTS AND REPORTS Every command decides by where it runs: at the prompt a Spectre.Console view, shown a screen at a time (any key: next page, A: the rest; -NoPaging to turn paging off) piped onward the objects, no view (| Where-Object, ...) -PassThru the view and the objects -NoDisplay the objects only (scripts, scheduled tasks) PowerShell can't tell "$r = Get-AACFirewallRule" from a plain call, so add -PassThru or -NoDisplay to keep the objects in a variable. -CsvPath, -PdfPath and -HtmlPath write reports. With any of them the console shows only the title, the progress and the files written - the report is in the files. Paths are relative to the current location, missing folders are created and existing files are overwritten. The HTML reports are single, self-contained files that work offline: clickable tiles and charts that filter the tables, search, filter drop-downs, sortable columns, grouping with subtotals, Azure portal links and a CSV download of the rows shown. Every command shows the same progress display: the title, then one line per step with a bar, a percentage and the elapsed time. Without an interactive terminal (CI, redirected output) each finished step is one plain line. PSRULE FOR AZURE Invoke-AACPSRule runs PSRule for Azure (the PSRule.Rules.Azure module, installed with this one) on every resource, resource group and subscription you can see, or those in -SubscriptionId. Invoke-AACPSRule Invoke-AACPSRule -HtmlPath .\PSRule.html -FailedOnly Invoke-AACPSRule -Rule 'Azure.Storage.*' -ExcludeRule 'Azure.Storage.Name' Invoke-AACPSRule -Baseline 'Azure.Pillar.Security' Rules: PSRule for Azure every rule of the installed module Azure.Admin.Console AAC.Resource.RequiredTags, AAC.ResourceGroup.RequiredTags and AAC.Resource.AllowedTagValues - off until configured (PSRule\Rules in the module folder) custom your rule files or folders, from -RulePath -Rule and -ExcludeRule take names or wildcards. -Configuration passes settings to the rules: Invoke-AACPSRule -Configuration @{ AAC_REQUIRED_TAGS = @('Owner', 'CostCenter') AAC_ALLOWED_TAG_VALUES = @{ Environment = @('prod', 'dev') } AZURE_RESOURCE_ALLOWED_LOCATIONS = @('uksouth', 'ukwest') } The data PSRule needs is what Export-AzRuleData exports, read with the Connect-AAC sign-in instead of the Az modules: Resource Graph for the resources, then Azure Resource Manager for the child settings PSRule looks at. PSRule runs in a pwsh process of its own. APPLICATION INSIGHTS Invoke-AACApplicationInsightQuery finds a Log Analytics workspace (-LogWorkspaceName) or Application Insights resource (-ApplicationInsightsName) by name and queries it through the Log Analytics or Application Insights query API, with a token from the Connect-AAC sign-in. Needs Log Analytics Reader (or Reader). Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' ` -Last 1d -MinimumSeverity Error -ExceptionType '*SqlException' Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' ` -Query 'AppRequests | summarize count() by Name' Without -Query it reads exceptions from the last -Last (default 2h), narrowed by -MinimumSeverity, -ExceptionType, -AppRoleName, -Search and -Top, flattened into one object each: time, severity, type and message, outer and innermost exceptions, the details array's type, message and severity level, the top stack frame, operation, app and client. With -Query each row keeps the query's columns. REQUIREMENTS - PowerShell 7.2 or later. PDF export needs PowerShell 7.4 or later on Windows. Everything else works on Windows, Linux and macOS. - PSRule.Rules.Azure 1.47 or later. It is installed with the module. - A browser for Connect-AAC, and Reader access to the subscriptions. SECURITY - The sign-in is kept only in memory for the PowerShell session. It is never written to disk. Disconnect-AAC forgets it. - No client secret is used. PKCE protects the sign-in code, and the redirect goes only to localhost. - The bundled Spectre.Console and PDFsharp/MigraDoc assemblies in lib\ are checked against pinned SHA-256 hashes before they load. A changed file is refused. TROUBLESHOOTING A command fails At the console, the step that was running turns red and a panel shows what failed, that step and what to do. The command then stops with its own error: try/catch, $Error and -ErrorVariable work as usual, and FullyQualifiedErrorId is AzureRequestFailed<status>, CommandFailed or InternalError. There's no panel in non-interactive output or with -ErrorAction SilentlyContinue. InternalError is a bug in the module; its message gives the file and line. Please report it at https://github.com/ChendrayanV/Azure.Admin.Console/issues. Symbols show as plain ASCII (*, ->, +, -) The console isn't UTF-8 (often code page 437 or 850), so the module draws its symbols in ASCII rather than letting them print as ?. For the full display, run [Console]::OutputEncoding = [Text.Encoding]::UTF8 (add it to your $PROFILE to keep it) and import the module again. "requires a minimum Windows PowerShell version of '7.2'" The module runs on PowerShell 7.2 or later (pwsh), not Windows PowerShell 5.1. Install it with: winget install Microsoft.PowerShell "Not connected to Azure" Run Connect-AAC in the same PowerShell session first. Sign-in times out Finish signing in within 180 seconds, or pass -TimeoutSeconds. Some tenants block the Azure CLI client ID. If yours does, pass your own App Registration's -ClientId (platform "Mobile and desktop applications", redirect URI http://localhost). Nothing is returned The account may not have Reader access on the subscriptions, or the filters matched nothing. Try again without -SubscriptionId or the other filters. PDF export fails on Linux, macOS or PowerShell 7.2 or 7.3 PDF export needs Windows and PowerShell 7.4 or later. Use -CsvPath or -HtmlPath instead. SEE ALSO Get-Help Connect-AAC -Full Get-Help Get-AACAdvisorRecommendation -Full Get-Help Get-AACFirewallRule -Full Get-Help Invoke-AACPSRule -Full Get-Help Invoke-AACApplicationInsightQuery -Full https://azure.github.io/PSRule.Rules.Azure/ https://learn.microsoft.com/azure/governance/resource-graph/ |