en-US/about_Azure.Admin.Console.help.txt

TOPIC
    about_Azure.Admin.Console
 
SHORT DESCRIPTION
    Azure admin reports and checks from PowerShell, over plain REST, with no
    Az or Microsoft.Graph modules.
 
LONG DESCRIPTION
    Azure.Admin.Console signs you in to Azure with your browser, then reads
    your estate through Azure Resource Graph and the Azure Resource Manager
    REST API. It turns what it reads into:
 
      - a colourful Spectre.Console view at the prompt,
      - flat PowerShell objects you can filter, group and sort,
      - CSV files written with Export-Csv (one row per item, the same
        columns on every row, ready for Excel or Power BI),
      - PDF reports laid out for people who don't use PowerShell,
      - interactive HTML reports that work offline.
 
    Nothing in Azure is ever changed. Reader access to the subscriptions is
    enough for every command but one: Get-AACStorageAccountContainerSize
    reads blobs, which needs a data role (Storage Blob Data Reader) or an
    account SAS (-AuthMode).
 
COMMANDS
    Connect-AAC
        Signs in with an interactive browser flow (OAuth 2.0 authorization
        code with PKCE and a localhost redirect). No app registration is
        needed: it uses the Azure CLI's public client ID, pre-consented in
        every Entra ID tenant, unless you pass -ClientId.
 
    Disconnect-AAC
        Forgets the sign-in.
 
    Get-AACAdvisorRecommendation
        A consolidated, flattened view of every Azure Advisor
        recommendation (Cost, Security, Reliability, Operational excellence,
        Performance), with estimated savings, retirement dates and
        postponed/dismissed status.
 
    Get-AACFirewallRule
        Every Azure Firewall Policy rule (DNAT, network, application) with
        IP Groups resolved, searchable by source, destination, port and
        protocol. Allow in green, Deny in red, DNAT in orange.
 
    Show-AACResource
        A colourful bar chart of your resources by type, location,
        resource group or subscription; -HtmlPath writes a full inventory.
 
    Get-AACInventory
        The tenant as a tree: management groups, subscriptions, resource
        groups and resources, with counts at every level; empty resource
        groups flagged; the Defender for Cloud secure score and, with -Cost,
        the cost month to date and last month at every level. A console
        tree, objects, and CSV, PDF and interactive HTML reports.
 
    Get-AACNetworkSecurityGroup
        A detailed assessment of network security groups: associations,
        every rule, flow logs and diagnostic settings, and findings by
        severity - open to the internet, shadowed rules, subnet and NIC
        NSGs that disagree, unassociated NSGs, logging gaps.
 
    Show-AACResourceMap
        A map of one or more resource groups, opened in your browser: the
        resources with their Azure icons in subscription, resource group,
        VNet and subnet boxes, with their connections, dependencies and
        network paths (peering, private links, routes through a firewall).
        Unattached resources are flagged. Saves as PNG or JPEG.
 
    Show-AACCost
        Subscription costs from Cost Management: month to date by
        subscription, service and resource group, and the monthly trend.
 
    Invoke-AACPSRule
        PSRule for Azure (500+ Well-Architected rules), the module's own
        naming and tag rules (AAC.*) and your custom rules on the live
        estate. -Rule 'AAC.*' reads only names, types and tags.
 
    Get-AACSecurityPosture
        Microsoft Defender for Cloud and Azure Policy in one report: secure
        scores, recommendations, alerts, Defender plans, regulatory and
        policy compliance - one list of findings.
 
    Get-AACSkuAvailability
        Which VM sizes you can use for virtual machines or AKS node pools in
        a region and its availability zones - restrictions, vCPU quota and
        AKS's rules - and why not. Read-only.
 
    Get-AACPolicyState
        Azure Policy compliance for every resource - one row per resource
        and policy - by management group, subscription or resource group.
 
    Get-AACAssignedPolicy
        What is assigned: every Azure Policy assignment and its parameters,
        one row per assignment and parameter - the default, assigned and
        effective value - with the resource types the policy applies to,
        read from its rule with the parameters resolved. With
        -SubscriptionId or -ManagementGroupId, the assignments inherited
        from the management groups above are included and marked.
 
    Get-AACStorageAccountContainerSize
        How much is stored in every blob container: blobs, bytes, access
        tiers, snapshots, versions and deleted blobs, the newest change and
        the largest blobs. Containers are read in parallel, 5,000 blobs a
        page, and added up as the pages arrive (about 275,000 blobs a
        second). -AuthMode EntraId (Storage Blob Data Reader), AccountSas
        or Auto.
 
    Get-AACEntraGroupMembership
        Entra ID groups and everyone in them - direct and through nested
        groups - one row per group and member, from Microsoft Graph with the
        Connect-AAC sign-in.
 
    Invoke-AACApplicationInsightQuery
        Application Insights exceptions, flattened, from a Log Analytics
        workspace or an Application Insights resource - or any KQL query.
 
    Get-Help <command> -Full shows every parameter and example.
 
GETTING STARTED
        Import-Module Azure.Admin.Console
        Connect-AAC
 
        # Advisor: the console view, then everything to CSV, PDF and HTML
        Get-AACAdvisorRecommendation
        Get-AACAdvisorRecommendation -CsvPath .\Adv.csv -PdfPath .\Adv.pdf -HtmlPath .\Adv.html
 
        # A map of two resource groups, in the browser
        Show-AACResourceMap -ResourceGroupName 'rg-hub', 'rg-spoke-app'
 
        # Firewall rules that let 10.1.2.3 reach 10.0.0.4 on UDP 53
        Get-AACFirewallRule -SourceAddress 10.1.2.3 `
            -DestinationAddress 10.0.0.4 -Port 53 -Protocol UDP
 
        # What you run, and what it costs
        Show-AACResource
        Show-AACCost
 
        # What is assigned to a subscription, with every parameter's value
        Get-AACAssignedPolicy -SubscriptionId '00000000-0000-0000-0000-000000000000'
 
        # Every blob container, with its size and access tiers
        Get-AACStorageAccountContainerSize -AuthMode Auto -HtmlPath .\Storage.html
 
        # PSRule for Azure on the live estate, as an HTML report
        Invoke-AACPSRule -HtmlPath .\PSRule.html
 
        # The last 2 hours of exceptions
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-contoso-prod'
 
CONSOLE VIEW, OBJECTS AND REPORTS
    Every command decides by where it runs:
 
        at the prompt a Spectre.Console view, shown a screen at a time
                        (any key: next page, A: the rest; -NoPaging to
                        turn paging off)
        piped onward the objects, no view (| Where-Object, ...)
        -PassThru the view and the objects
        -NoDisplay the objects only (scripts, scheduled tasks)
 
    PowerShell can't tell "$r = Get-AACFirewallRule" from a plain call,
    so add -PassThru or -NoDisplay to keep the objects in a variable.
 
    -CsvPath, -PdfPath and -HtmlPath write reports. With any of them the
    console shows only the title, the progress and the files written - the
    report is in the files. Paths are relative to the current location,
    missing folders are created and existing files are overwritten.
 
    The HTML reports are single, self-contained files that work offline:
    clickable tiles and charts that filter the tables, search, filter
    drop-downs, sortable columns, grouping with subtotals, Azure portal
    links and a CSV download of the rows shown.
 
    Every command shows the same progress display: the title, then one line
    per step with a bar, a percentage and the elapsed time. Without an
    interactive terminal (CI, redirected output) each finished step is one
    plain line.
 
PSRULE FOR AZURE
    Invoke-AACPSRule runs PSRule for Azure (the PSRule.Rules.Azure module,
    installed with this one) on every resource, resource group and
    subscription you can see, or those in -SubscriptionId.
 
        Invoke-AACPSRule
        Invoke-AACPSRule -HtmlPath .\PSRule.html -FailedOnly
        Invoke-AACPSRule -Rule 'Azure.Storage.*' -ExcludeRule 'Azure.Storage.Name'
        Invoke-AACPSRule -Baseline 'Azure.Pillar.Security'
 
    Rules:
        PSRule for Azure every rule of the installed module
        Azure.Admin.Console AAC.Resource.RequiredTags,
                             AAC.ResourceGroup.RequiredTags and
                             AAC.Resource.AllowedTagValues - off until
                             configured (PSRule\Rules in the module folder)
        custom your rule files or folders, from -RulePath
 
    -Rule and -ExcludeRule take names or wildcards. -Configuration passes
    settings to the rules:
 
        Invoke-AACPSRule -Configuration @{
            AAC_REQUIRED_TAGS = @('Owner', 'CostCenter')
            AAC_ALLOWED_TAG_VALUES = @{ Environment = @('prod', 'dev') }
            AZURE_RESOURCE_ALLOWED_LOCATIONS = @('uksouth', 'ukwest')
        }
 
    The data PSRule needs is what Export-AzRuleData exports, read with the
    Connect-AAC sign-in instead of the Az modules: Resource Graph for the
    resources, then Azure Resource Manager for the child settings PSRule
    looks at. PSRule runs in a pwsh process of its own.
 
APPLICATION INSIGHTS
    Invoke-AACApplicationInsightQuery finds a Log Analytics workspace
    (-LogWorkspaceName) or Application Insights resource
    (-ApplicationInsightsName) by name and queries it through the Log
    Analytics or Application Insights query API, with a token from the
    Connect-AAC sign-in. Needs Log Analytics Reader (or Reader).
 
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod'
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' `
            -Last 1d -MinimumSeverity Error -ExceptionType '*SqlException'
        Invoke-AACApplicationInsightQuery -LogWorkspaceName 'law-prod' `
            -Query 'AppRequests | summarize count() by Name'
 
    Without -Query it reads exceptions from the last -Last (default 2h),
    narrowed by -MinimumSeverity, -ExceptionType, -AppRoleName, -Search
    and -Top, flattened into one object each: time, severity, type and
    message, outer and innermost exceptions, the details array's type,
    message and severity level, the top stack frame, operation, app and
    client. With -Query each row keeps the query's columns.
 
BLOB STORAGE
    Get-AACStorageAccountContainerSize finds the storage accounts with Azure
    Resource Graph and lists their containers through Azure Resource
    Manager (Reader is enough), then lists the blobs from each account's
    blob service, which needs data access:
 
        -AuthMode EntraId the default: your sign-in, with the Storage
                              Blob Data Reader role (or Contributor or
                              Owner of the data) on the account
        -AuthMode AccountSas a read-and-list account SAS, valid 4 hours,
                              from listAccountSas - needs permission to list
                              the account's keys; kept in memory only
        -AuthMode Auto Entra ID, then an account SAS for the accounts
                              that refuse Entra ID for want of a data role
 
    Accounts behind a firewall or private endpoint can only be read from a
    network they allow. Whatever couldn't be read is listed with Azure
    Storage's reason and what to do about it.
 
REQUIREMENTS
    - PowerShell 7.2 or later. PDF export needs PowerShell 7.4 or later on
      Windows. Everything else works on Windows, Linux and macOS.
    - PSRule.Rules.Azure 1.47 or later. It is installed with the module.
    - A browser for Connect-AAC, and Reader access to the subscriptions.
      Get-AACStorageAccountContainerSize also needs data access to the
      blobs (see BLOB STORAGE).
 
SECURITY
    - The sign-in is kept only in memory for the PowerShell session. It is
      never written to disk. Disconnect-AAC forgets it.
    - No client secret is used. PKCE protects the sign-in code, and the
      redirect goes only to localhost.
    - The bundled Spectre.Console and PDFsharp/MigraDoc assemblies in lib\
      are checked against pinned SHA-256 hashes before they load. A changed
      file is refused.
 
TROUBLESHOOTING
    A command fails
        At the console, the step that was running turns red and a panel
        shows what failed, that step and what to do. The command then stops
        with its own error: try/catch, $Error and -ErrorVariable work as
        usual, and FullyQualifiedErrorId is AzureRequestFailed<status>,
        CommandFailed or InternalError. There's no panel in non-interactive
        output or with -ErrorAction SilentlyContinue. InternalError is a bug
        in the module; its message gives the file and line. Please report
        it at https://github.com/ChendrayanV/Azure.Admin.Console/issues.
 
    "The pipeline has been stopped."
        Before v0.13.0, piping a command to Select-Object -First ended it
        with this error. It isn't a failure: from v0.13.0 the command just
        stops and the rest of the script carries on. Ctrl+C still stops
        everything.
 
    Symbols show as plain ASCII (*, ->, +, -)
        The console isn't UTF-8 (often code page 437 or 850), so the module
        draws its symbols in ASCII rather than letting them print as ?.
        For the full display, run
        [Console]::OutputEncoding = [Text.Encoding]::UTF8 (add it to your
        $PROFILE to keep it) and import the module again.
 
    "requires a minimum Windows PowerShell version of '7.2'"
        The module runs on PowerShell 7.2 or later (pwsh), not Windows
        PowerShell 5.1. Install it with: winget install Microsoft.PowerShell
 
    "Not connected to Azure"
        Run Connect-AAC in the same PowerShell session first.
 
    Sign-in times out
        Finish signing in within 180 seconds, or pass -TimeoutSeconds.
        Some tenants block the Azure CLI client ID. If yours does, pass your
        own App Registration's -ClientId (platform "Mobile and desktop
        applications", redirect URI http://localhost).
 
    Nothing is returned
        The account may not have Reader access on the subscriptions, or the
        filters matched nothing. Try again without -SubscriptionId or the
        other filters.
 
    AuthorizationPermissionMismatch (Get-AACStorageAccountContainerSize)
        Your sign-in has no data role on the storage account. Give it
        Storage Blob Data Reader, or run with -AuthMode Auto or AccountSas.
        AuthorizationFailure means the account's firewall refused this
        network.
 
    PDF export fails on Linux, macOS or PowerShell 7.2 or 7.3
        PDF export needs Windows and PowerShell 7.4 or later. Use -CsvPath
        or -HtmlPath instead.
 
SEE ALSO
    Get-Help Connect-AAC -Full
    Get-Help Get-AACAdvisorRecommendation -Full
    Get-Help Get-AACFirewallRule -Full
    Get-Help Invoke-AACPSRule -Full
    Get-Help Invoke-AACApplicationInsightQuery -Full
    Get-Help Get-AACAssignedPolicy -Full
    Get-Help Get-AACStorageAccountContainerSize -Full
    https://azure.github.io/PSRule.Rules.Azure/
    https://learn.microsoft.com/azure/governance/resource-graph/