Azure.Admin.Console
0.13.0
Minimum PowerShell version
7.2
Installation Options
Owners
Copyright
(c) 2026 Chendrayan Venkatesan. Licensed under the MIT License.
Package Details
Author(s)
- Chendrayan Venkatesan
Tags
Azure AzureAdvisor AzureFirewall CostManagement Inventory FirewallPolicy ResourceGraph Governance EntraID MicrosoftGraph Groups DefenderForCloud Storage BlobStorage AzurePolicy SecureScore Report PDF CSV ApplicationInsights LogAnalytics KQL PSRule WellArchitected HTML Compliance SpectreConsole REST PKCE Windows Linux MacOS
Functions
Connect-AAC Disconnect-AAC Get-AACAdvisorRecommendation Get-AACAssignedPolicy Get-AACEntraGroupMembership Get-AACFirewallRule Get-AACInventory Get-AACNetworkSecurityGroup Get-AACPolicyState Get-AACSecurityPosture Get-AACSkuAvailability Get-AACStorageAccountContainerSize Invoke-AACApplicationInsightQuery Invoke-AACPSRule Show-AACCost Show-AACResource Show-AACResourceMap
PSEditions
Dependencies
-
- PSRule.Rules.Azure (>= 1.47.0)
Release Notes
v0.13.0 - NEW Get-AACAssignedPolicy: every Azure Policy assignment and its parameters, one row per assignment and parameter - default, assigned and effective value, where it comes from, allowed values - with the resource types the policy applies to (its rule's type conditions, parameters resolved; for an initiative, the member policies using each parameter); -SubscriptionId or -ManagementGroupId include assignments inherited from management groups; a few Resource Graph queries, not one call per assignment; console, objects, CSV and HTML. NEW Get-AACStorageAccountContainerSize: every blob container's blobs, size per access tier, snapshots, versions and deleted blobs, newest change and largest blobs; containers read in parallel (-ThrottleLimit), 5,000 blobs a page, added up as they arrive by a parser compiled on first use (about 275,000 blobs a second), memory flat; -AuthMode EntraId (Storage Blob Data Reader), AccountSas (4-hour read-only SAS, in memory only) or Auto; what can't be read is reported with the reason and what to do; console, objects, CSV (-CsvPath, -BlobCsvPath) and HTML. NEW Get-AACSkuAvailability: which VM sizes you can use for virtual machines or AKS node pools in a region and its availability zones - the subscription's region and zone restrictions, family and regional vCPU quota for -NodeCount, AKS's rules, the zone mapping, an AKS cluster's node pools (-ClusterName) - and why not; read-only REST, nothing deployed; -Series, -Sku, -Architecture, -Zone; console, objects, CSV, HTML and PDF. NEW Get-AACPolicyState: Azure Policy compliance for every resource (one KQL query) - by -ManagementGroupId, -SubscriptionId, -ResourceGroupName, -ComplianceState; one row per resource and policy with initiative, assignment, scope, effect; compliance per resource, assignment, subscription, resource group and policy; console, objects, CSV, HTML and PDF. NEW Get-AACInventory -Insight: VM sizes, operating systems, power states, Azure and Arc, storage replication, database tiers, tag coverage; what needs attention (unattached disks, unused public IPs and NICs, VMs stopped but billed, classic resources, nearly full subnets, connections down) with its cost; subnet IP usage; donut charts in HTML. Get-AACNetworkSecurityGroup counts the VMs each NSG protects. NEW Get-AACSecurityPosture: Defender for Cloud and Azure Policy in one report - secure scores and controls, recommendations with their control and remediation link, active alerts, Defender plans, regulatory compliance traced to failing resources, and policy compliance per assignment - one list of findings; -Section, -ResourceGroupName, -Tag, -Standard; console, objects, CSV, HTML and PDF. NEW Get-AACEntraGroupMembership: Entra ID groups (-GroupName, -GroupNameStartsWith, or all) and everyone in them, direct and through nested groups followed to the end, flattened to one row per group and member (group type and source; member type, UPN, member or guest, enabled or disabled; Direct, Nested with the path, or Empty) - console view with member trees, objects, CSV (-CsvPath or -OutputPath), interactive HTML and PDF; uses the Connect-AAC sign-in for Microsoft Graph (no second prompt), reads 8 at a time. NEW Get-AACNetworkSecurityGroup: a detailed assessment of network security groups (all of them by default, or by -SubscriptionId, -ResourceGroupName and -Name, wildcards allowed): metadata, the subnets and NICs each is applied to, every rule in evaluation order (5-tuple and action, application security groups by name), diagnostic settings and their destinations, NSG and virtual network flow logs with retention and Traffic Analytics. Findings by severity with what to do: rules open to the internet (every port, management and database ports, wide ranges, ICMP), everything allowed from the virtual network, shadowed rules, unassociated NSGs, subnet and NIC NSGs that disagree (both evaluated as Azure does), missing or short-lived flow logs, NSG flow logs retiring on 30 September 2027, missing diagnostic settings, the rule limit. Console view, AAC.NetworkSecurityGroup objects, CSV of every rule, interactive HTML (NSGs, findings, rules, associations, logging) and PDF (a page per NSG with its rules). NEW Get-AACInventory -Cost: the actual cost month to date and last month of every resource, rolled up to resource groups, subscriptions, management groups and the tenant - one Cost Management query for the tenant root group when the billing account allows it, otherwise one per subscription, 3 at a time; deleted resources and charges not tied to a resource under their subscription; never converted between currencies; in the console, HTML, PDF and objects. NEW AAC.Resource.Naming: PSRule naming checks for resource groups and about 30 resource types against the Cloud Adoption Framework abbreviations, with no setting needed (AAC_NAMING_PATTERNS and AAC_NAMING_IGNORE to change them); a naming-only run reads just those types and no child settings. Tag rules read their tags from Get-AACTagDefault in PSRule\Rules\AAC.Tags.Rule.ps1, and a tag rule with no tags to check says so. NOTHING CUT OFF: the PSRule view lists every failing resource (up to 50 per rule) with its whole reason; object tables at the prompt wrap long text (Azure.Admin.Console.Format.ps1xml); the NSG, inventory and Application Insights views wrap and list everything. Invoke-AACPSRule reads only names, types and tags when only AAC.* rules run (-NoExpand for your own), and refuses a -Rule that is a file path or matches no rule. FASTER: every Azure call shares one pooled HTTPS connection with the same retry rules; independent Resource Graph queries run in parallel (Get-AACInventory, Get-AACNetworkSecurityGroup, Get-AACFirewallRule, Get-AACAdvisorRecommendation, Show-AACResource, Show-AACResourceMap); NSG diagnostic settings are read 12 at a time; Show-AACCost reads 3 subscriptions at a time. FIXED: piping any command to Select-Object -First no longer fails with "The pipeline has been stopped." - the command just stops and the script carries on (Ctrl+C still stops everything). Invoke-AACPSRule reads resource settings in parallel (12 at a time, a level of children at a time): API Management services with many APIs and operations take seconds instead of minutes. Full history: CHANGELOG.md.
FileList
- Azure.Admin.Console.nuspec
- Azure.Admin.Console.Format.ps1xml
- Private\Get-AACPSRulePlan.ps1
- Private\Show-AACExceptionView.ps1
- Private\Write-AACSkuAvailabilityPdf.ps1
- Private\Get-AACResourceMapAsset.ps1
- Private\Show-AACFirewallRuleView.ps1
- Private\Write-AACStorageSizeHtml.ps1
- Azure.Admin.Console.psd1
- Private\Get-AACRetryDelay.ps1
- Private\Show-AACGroupMembershipView.ps1
- PSRule\PSRuleRunner.ps1
- Azure.Admin.Console.psm1
- Private\Get-AACRuleData.ps1
- Private\Show-AACInventoryView.ps1
- Public\Connect-AAC.ps1
- CHANGELOG.md
- Private\Get-AACRuleDefault.ps1
- Private\Show-AACNsgView.ps1
- Public\Disconnect-AAC.ps1
- LICENSE
- Private\Get-AACTableSuggestion.ps1
- Private\Show-AACPanel.ps1
- Public\Get-AACAdvisorRecommendation.ps1
- README.md
- Private\Get-AACWorkspaceComponent.ps1
- Private\Show-AACPolicyStateView.ps1
- Public\Get-AACAssignedPolicy.ps1
- en-US\about_Azure.Admin.Console.help.txt
- Private\Import-AACBlobListParser.ps1
- Private\Show-AACPSRuleView.ps1
- Public\Get-AACEntraGroupMembership.ps1
- en-US\Azure.Admin.Console-help.xml
- Private\Import-AACPdfLibrary.ps1
- Private\Show-AACQueryResultView.ps1
- Public\Get-AACFirewallRule.ps1
- lib\Spectre.Console.dll
- Private\Invoke-AACArmParallel.ps1
- Private\Show-AACSecurityPostureView.ps1
- Public\Get-AACInventory.ps1
- lib\Spectre.Console.LICENSE.md
- Private\Invoke-AACArmRequest.ps1
- Private\Show-AACSkuAvailabilityView.ps1
- Public\Get-AACNetworkSecurityGroup.ps1
- Private\ConvertFrom-AACBlobList.ps1
- Private\Invoke-AACBrowserSignIn.ps1
- Private\Show-AACStorageSizeView.ps1
- Public\Get-AACPolicyState.ps1
- Private\ConvertFrom-AACJwt.ps1
- Private\Invoke-AACCostBatch.ps1
- Private\Show-AACTileRow.ps1
- Public\Get-AACSecurityPosture.ps1
- Private\ConvertFrom-AACQueryString.ps1
- Private\Invoke-AACCostQuery.ps1
- Private\Test-AACErrorPanel.ps1
- Public\Get-AACSkuAvailability.ps1
- Private\ConvertTo-AACAssignedPolicy.ps1
- Private\Invoke-AACExport.ps1
- Private\Test-AACFirewallMatch.ps1
- Public\Get-AACStorageAccountContainerSize.ps1
- Private\ConvertTo-AACBase64Url.ps1
- Private\Invoke-AACGraphBatch.ps1
- Private\Update-AACProgress.ps1
- Public\Invoke-AACApplicationInsightQuery.ps1
- Private\ConvertTo-AACColor.ps1
- Private\Invoke-AACHttp.ps1
- Private\Write-AACAdvisorRecommendationHtml.ps1
- Public\Invoke-AACPSRule.ps1
- Private\ConvertTo-AACExceptionRecord.ps1
- Private\Invoke-AACHttpBatch.ps1
- Private\Write-AACAdvisorRecommendationPdf.ps1
- Public\Show-AACCost.ps1
- Private\ConvertTo-AACGroupMembership.ps1
- Private\Invoke-AACLogQuery.ps1
- Private\Write-AACAssignedPolicyHtml.ps1
- Public\Show-AACResource.ps1
- Private\ConvertTo-AACInventory.ps1
- Private\Invoke-AACPagedOutput.ps1
- Private\Write-AACCostHtml.ps1
- Public\Show-AACResourceMap.ps1
- Private\ConvertTo-AACInventoryInsight.ps1
- Private\Invoke-AACPagedRestMethod.ps1
- Private\Write-AACCostPdf.ps1
- lib\azure-icons\azure-icons.json
- Private\ConvertTo-AACNsgAssessment.ps1
- Private\Invoke-AACProgress.ps1
- Private\Write-AACExceptionHtml.ps1
- lib\azure-icons\SOURCES.md
- Private\ConvertTo-AACPolicyState.ps1
- Private\Invoke-AACPSRuleEngine.ps1
- Private\Write-AACFirewallRuleHtml.ps1
- lib\elk\elk.bundled.js
- Private\ConvertTo-AACPSObject.ps1
- Private\Invoke-AACResourceGraphQuery.ps1
- Private\Write-AACFirewallRulePdf.ps1
- lib\elk\LICENSE.md
- Private\ConvertTo-AACResourceMap.ps1
- Private\New-AACBlobTally.ps1
- Private\Write-AACGroupMembershipHtml.ps1
- lib\elk\SOURCES.md
- Private\ConvertTo-AACSecurityControl.ps1
- Private\New-AACPdfDocument.ps1
- Private\Write-AACGroupMembershipPdf.ps1
- lib\pdf\Microsoft.Extensions.DependencyInjection.Abstractions.dll
- Private\ConvertTo-AACSecurityPosture.ps1
- Private\New-AACPkceCode.ps1
- Private\Write-AACHtmlReport.ps1
- lib\pdf\Microsoft.Extensions.LICENSE.txt
- Private\ConvertTo-AACSecurityRecommendation.ps1
- Private\Open-AACFile.ps1
- Private\Write-AACInventoryHtml.ps1
- lib\pdf\Microsoft.Extensions.Logging.Abstractions.dll
- Private\ConvertTo-AACSkuAvailability.ps1
- Private\Read-AACBlobContainer.ps1
- Private\Write-AACInventoryPdf.ps1
- lib\pdf\Microsoft.Extensions.THIRD-PARTY-NOTICES.txt
- Private\ConvertTo-AACStorageContainerRow.ps1
- Private\Read-AACEntraGroup.ps1
- Private\Write-AACMarkup.ps1
- lib\pdf\MigraDoc.DocumentObjectModel.dll
- Private\ConvertTo-AACStorageSizeReport.ps1
- Private\Read-AACInventoryCost.ps1
- Private\Write-AACNsgHtml.ps1
- lib\pdf\MigraDoc.Rendering.dll
- Private\DataReport.html
- Private\Resolve-AACInsightsTable.ps1
- Private\Write-AACNsgPdf.ps1
- lib\pdf\PDFsharp-MigraDoc.LICENSE.txt
- Private\Format-AACByteSize.ps1
- Private\Resolve-AACLogResource.ps1
- Private\Write-AACPolicyStateHtml.ps1
- lib\pdf\PdfSharp.Charting.dll
- Private\Get-AACAccessToken.ps1
- Private\ResourceMap.html
- Private\Write-AACPolicyStatePdf.ps1
- lib\pdf\PdfSharp.dll
- Private\Get-AACByteUnit.ps1
- Private\Save-AACPdfDocument.ps1
- Private\Write-AACPSRuleHtml.ps1
- lib\pdf\PdfSharp.Shared.dll
- Private\Get-AACDefenderQuery.ps1
- Private\Send-AACHttpRequest.ps1
- Private\Write-AACPSRulePdf.ps1
- lib\pdf\PdfSharp.System.dll
- Private\Get-AACErrorMessage.ps1
- Private\Show-AACAdvisorSummary.ps1
- Private\Write-AACQueryResultHtml.ps1
- lib\pdf\SOURCES.md
- Private\Get-AACFreeLoopbackPort.ps1
- Private\Show-AACAdvisorTable.ps1
- Private\Write-AACResourceHtml.ps1
- PSRule\Rules\AAC.Naming.Rule.ps1
- Private\Get-AACGlyph.ps1
- Private\Show-AACAssignedPolicyView.ps1
- Private\Write-AACResourceMapHtml.ps1
- PSRule\Rules\AAC.Tags.Rule.ps1
- Private\Get-AACHttpClient.ps1
- Private\Show-AACBarChart.ps1
- Private\Write-AACRule.ps1
- PSRule\Rules\en\AAC.Resource.AllowedTagValues.md
- Private\Get-AACInsightQuery.ps1
- Private\Show-AACBreakdownChart.ps1
- Private\Write-AACSecurityPostureHtml.ps1
- PSRule\Rules\en\AAC.Resource.Naming.md
- Private\Get-AACPolicyResourceType.ps1
- Private\Show-AACCostNotice.ps1
- Private\Write-AACSecurityPosturePdf.ps1
- PSRule\Rules\en\AAC.Resource.RequiredTags.md
- Private\Get-AACPolicyStateQuery.ps1
- Private\Show-AACError.ps1
- Private\Write-AACSkuAvailabilityHtml.ps1
- PSRule\Rules\en\AAC.ResourceGroup.RequiredTags.md
- Private\Get-AACPropertyValue.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.13.0 (current version) | 6 | 10/1/2026 |
| 0.12.0 | 8 | 9/28/2026 |
| 0.11.0 | 10 | 9/27/2026 |