en-US/about_Azure.Admin.Console.help.txt
|
TOPIC
about_Azure.Admin.Console SHORT DESCRIPTION Azure admin reports and checks from PowerShell, over plain REST, with no Az or Microsoft.Graph modules. LONG DESCRIPTION Azure.Admin.Console signs you in to Azure with your browser, then reads your estate through Azure Resource Graph and the Azure Resource Manager REST API. It turns what it reads into: - a colourful Spectre.Console view at the prompt, - flat PowerShell objects you can filter, group and sort, - CSV files written with Export-Csv (one row per item, the same columns on every row, ready for Excel or Power BI), - PDF reports laid out for people who don't use PowerShell, - interactive HTML reports that work offline. Nothing in Azure is ever changed. Reader access to the subscriptions is enough for every command but one: Get-AACStorageAccountContainerSize reads blobs, which needs a data role (Storage Blob Data Reader) or an account SAS (-AuthMode). COMMANDS Connect-AAC Signs in with an interactive browser flow (OAuth 2.0 authorization code with PKCE and a localhost redirect). No app registration is needed: it uses the Azure CLI's public client ID, pre-consented in every Entra ID tenant, unless you pass -ClientId. Disconnect-AAC Forgets the sign-in. Get-AACAdvisorRecommendation A consolidated, flattened view of every Azure Advisor recommendation (Cost, Security, Reliability, Operational excellence, Performance), with estimated savings, retirement dates and postponed/dismissed status. Get-AACFirewallRule Every Azure Firewall Policy rule (DNAT, network, application) with IP Groups resolved, searchable by source, destination, port and protocol. Allow in green, Deny in red, DNAT in orange. Show-AACResource A colourful bar chart of your resources by type, location, resource group or subscription; -HtmlPath writes a full inventory. Get-AACInventory The tenant as a tree: management groups, subscriptions, resource groups and resources, with counts at every level; empty resource groups flagged; the Defender for Cloud secure score and, with -Cost, the cost month to date and last month at every level. A console tree, objects, and CSV, PDF and interactive HTML reports. Get-AACNetworkSecurityGroup A detailed assessment of network security groups: associations, every rule, flow logs and diagnostic settings, and findings by severity - open to the internet, shadowed rules, subnet and NIC NSGs that disagree, unassociated NSGs, logging gaps. Show-AACResourceMap A map of one or more resource groups, opened in your browser: the resources with their Azure icons in subscription, resource group, VNet and subnet boxes, with their connections, dependencies and network paths (peering, private links, routes through a firewall). Unattached resources are flagged. Saves as PNG or JPEG. Show-AACCost Subscription costs from Cost Management: month to date by subscription, service and resource group, and the monthly trend. Invoke-AACPSRule PSRule for Azure (500+ Well-Architected rules), the module's own naming and tag rules (AAC.*) and your custom rules on the live estate. -Rule 'AAC.*' reads only names, types and tags. Get-AACSecurityPosture Microsoft Defender for Cloud and Azure Policy in one report: secure scores, recommendations, alerts, Defender plans, regulatory and policy compliance - one list of findings. Get-AACSkuAvailability Which VM sizes you can use for virtual machines or AKS node pools in a region and its availability zones - restrictions, vCPU quota and AKS's rules - and why not. Read-only. Get-AACPolicyState Azure Policy compliance for every resource - one row per resource and policy - by management group, subscription or resource group. Get-AACAssignedPolicy What is assigned: every Azure Policy assignment and its parameters, one row per assignment and parameter - the default, assigned and effective value - with the resource types the policy applies to, read from its rule with the parameters resolved. With -SubscriptionId or -ManagementGroupId, the assignments inherited from the management groups above are included and marked. Get-AACStorageAccountContainerSize How much is stored in every blob container: blobs, bytes, access tiers, snapshots, versions and deleted blobs, the newest change and the largest blobs. Containers are read in parallel, 5,000 blobs a page, and added up as the pages arrive (about 275,000 blobs a second). -AuthMode EntraId (Storage Blob Data Reader), AccountSas or Auto. Get-AACEntraGroupMembership Entra ID groups and everyone in them - direct and through nested groups - one row per group and member, from Microsoft Graph with the Connect-AAC sign-in. Invoke-AACApplicationInsightQuery Application Insights exceptions, flattened, from a Log Analytics workspace or an Application Insights resource - or any KQL query. Get-Help <command> -Full shows every parameter and example. GETTING STARTED Import-Module Azure.Admin.Console Connect-AAC # Advisor: the console view, then everything to CSV, PDF and HTML Get-AACAdvisorRecommendation Get-AACAdvisorRecommendation -CsvPath .\Adv.csv -PdfPath .\Adv.pdf -HtmlPath .\Adv.html # A map of two resource groups, in the browser Show-AACResourceMap -ResourceGroupName 'rg-hub', 'rg-spoke-app' # Firewall rules that let 10.1.2.3 reach 10.0.0.4 on UDP 53 Get-AACFirewallRule -SourceAddress 10.1.2.3 ` -DestinationAddress 10.0.0.4 -Port 53 -Protocol UDP # What you run, and what it costs Show-AACResource Show-AACCost # What is assigned to a subscription, with every parameter's value Get-AACAssignedPolicy -SubscriptionId '00000000-0000-0000-0000-000000000000' # Every blob container, with its size and access tiers Get-AACStorageAccountContainerSize -AuthMode Auto -HtmlPath .\Storage.html # PSRule for Azure on the live estate, as an HTML report Invoke-AACPSRule -HtmlPath .\PSRule.html # The last 2 hours of exceptions Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-contoso-prod' CONSOLE VIEW, OBJECTS AND REPORTS Every command decides by where it runs: at the prompt a Spectre.Console view, shown a screen at a time (any key: next page, A: the rest; -NoPaging to turn paging off) piped onward the objects, no view (| Where-Object, ...) -PassThru the view and the objects -NoDisplay the objects only (scripts, scheduled tasks) PowerShell can't tell "$r = Get-AACFirewallRule" from a plain call, so add -PassThru or -NoDisplay to keep the objects in a variable. -CsvPath, -PdfPath and -HtmlPath write reports. With any of them the console shows only the title, the progress and the files written - the report is in the files. Paths are relative to the current location, missing folders are created and existing files are overwritten. The HTML reports are single, self-contained files that work offline: clickable tiles and charts that filter the tables, search, filter drop-downs, sortable columns, grouping with subtotals, Azure portal links and a CSV download of the rows shown. Every command shows the same progress display: the title, then one line per step with a bar, a percentage and the elapsed time. Without an interactive terminal (CI, redirected output) each finished step is one plain line. PSRULE FOR AZURE Invoke-AACPSRule runs PSRule for Azure (the PSRule.Rules.Azure module, installed with this one) on every resource, resource group and subscription you can see, or those in -SubscriptionId. Invoke-AACPSRule Invoke-AACPSRule -HtmlPath .\PSRule.html -FailedOnly Invoke-AACPSRule -Rule 'Azure.Storage.*' -ExcludeRule 'Azure.Storage.Name' Invoke-AACPSRule -Baseline 'Azure.Pillar.Security' Rules: PSRule for Azure every rule of the installed module Azure.Admin.Console AAC.Resource.RequiredTags, AAC.ResourceGroup.RequiredTags and AAC.Resource.AllowedTagValues - off until configured (PSRule\Rules in the module folder) custom your rule files or folders, from -RulePath -Rule and -ExcludeRule take names or wildcards. -Configuration passes settings to the rules: Invoke-AACPSRule -Configuration @{ AAC_REQUIRED_TAGS = @('Owner', 'CostCenter') AAC_ALLOWED_TAG_VALUES = @{ Environment = @('prod', 'dev') } AZURE_RESOURCE_ALLOWED_LOCATIONS = @('uksouth', 'ukwest') } The data PSRule needs is what Export-AzRuleData exports, read with the Connect-AAC sign-in instead of the Az modules: Resource Graph for the resources, then Azure Resource Manager for the child settings PSRule looks at. PSRule runs in a pwsh process of its own. APPLICATION INSIGHTS Invoke-AACApplicationInsightQuery finds a Log Analytics workspace (-LogWorkspaceName) or Application Insights resource (-ApplicationInsightsName) by name and queries it through the Log Analytics or Application Insights query API, with a token from the Connect-AAC sign-in. Needs Log Analytics Reader (or Reader). Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' ` -Last 1d -MinimumSeverity Error -ExceptionType '*SqlException' Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' ` -Query 'AppRequests | summarize count() by Name' Without -Query it reads exceptions from the last -Last (default 2h), narrowed by -MinimumSeverity, -ExceptionType, -AppRoleName, -Search and -Top, flattened into one object each: time, severity, type and message, outer and innermost exceptions, the details array's type, message and severity level, the top stack frame, operation, app and client. With -Query each row keeps the query's columns. BLOB STORAGE Get-AACStorageAccountContainerSize finds the storage accounts with Azure Resource Graph and lists their containers through Azure Resource Manager (Reader is enough), then lists the blobs from each account's blob service, which needs data access: -AuthMode EntraId the default: your sign-in, with the Storage Blob Data Reader role (or Contributor or Owner of the data) on the account -AuthMode AccountSas a read-and-list account SAS, valid 4 hours, from listAccountSas - needs permission to list the account's keys; kept in memory only -AuthMode Auto Entra ID, then an account SAS for the accounts that refuse Entra ID for want of a data role Accounts behind a firewall or private endpoint can only be read from a network they allow. Whatever couldn't be read is listed with Azure Storage's reason and what to do about it. REQUIREMENTS - PowerShell 7.2 or later. PDF export needs PowerShell 7.4 or later on Windows. Everything else works on Windows, Linux and macOS. - PSRule.Rules.Azure 1.47 or later. It is installed with the module. - A browser for Connect-AAC, and Reader access to the subscriptions. Get-AACStorageAccountContainerSize also needs data access to the blobs (see BLOB STORAGE). SECURITY - The sign-in is kept only in memory for the PowerShell session. It is never written to disk. Disconnect-AAC forgets it. - No client secret is used. PKCE protects the sign-in code, and the redirect goes only to localhost. - The bundled Spectre.Console and PDFsharp/MigraDoc assemblies in lib\ are checked against pinned SHA-256 hashes before they load. A changed file is refused. TROUBLESHOOTING A command fails At the console, the step that was running turns red and a panel shows what failed, that step and what to do. The command then stops with its own error: try/catch, $Error and -ErrorVariable work as usual, and FullyQualifiedErrorId is AzureRequestFailed<status>, CommandFailed or InternalError. There's no panel in non-interactive output or with -ErrorAction SilentlyContinue. InternalError is a bug in the module; its message gives the file and line. Please report it at https://github.com/ChendrayanV/Azure.Admin.Console/issues. "The pipeline has been stopped." Before v0.13.0, piping a command to Select-Object -First ended it with this error. It isn't a failure: from v0.13.0 the command just stops and the rest of the script carries on. Ctrl+C still stops everything. Symbols show as plain ASCII (*, ->, +, -) The console isn't UTF-8 (often code page 437 or 850), so the module draws its symbols in ASCII rather than letting them print as ?. For the full display, run [Console]::OutputEncoding = [Text.Encoding]::UTF8 (add it to your $PROFILE to keep it) and import the module again. "requires a minimum Windows PowerShell version of '7.2'" The module runs on PowerShell 7.2 or later (pwsh), not Windows PowerShell 5.1. Install it with: winget install Microsoft.PowerShell "Not connected to Azure" Run Connect-AAC in the same PowerShell session first. Sign-in times out Finish signing in within 180 seconds, or pass -TimeoutSeconds. Some tenants block the Azure CLI client ID. If yours does, pass your own App Registration's -ClientId (platform "Mobile and desktop applications", redirect URI http://localhost). Nothing is returned The account may not have Reader access on the subscriptions, or the filters matched nothing. Try again without -SubscriptionId or the other filters. AuthorizationPermissionMismatch (Get-AACStorageAccountContainerSize) Your sign-in has no data role on the storage account. Give it Storage Blob Data Reader, or run with -AuthMode Auto or AccountSas. AuthorizationFailure means the account's firewall refused this network. PDF export fails on Linux, macOS or PowerShell 7.2 or 7.3 PDF export needs Windows and PowerShell 7.4 or later. Use -CsvPath or -HtmlPath instead. SEE ALSO Get-Help Connect-AAC -Full Get-Help Get-AACAdvisorRecommendation -Full Get-Help Get-AACFirewallRule -Full Get-Help Invoke-AACPSRule -Full Get-Help Invoke-AACApplicationInsightQuery -Full Get-Help Get-AACAssignedPolicy -Full Get-Help Get-AACStorageAccountContainerSize -Full https://azure.github.io/PSRule.Rules.Azure/ https://learn.microsoft.com/azure/governance/resource-graph/ |