LeastPrivilegedMSGraph.psd1

#
# Module manifest for module 'LeastPrivilegedMSGraph'
#
# Generated by: Morten Mynster
#
# Generated on: 2025
#

@{

    # Script module or binary module file associated with this manifest.
    RootModule           = 'LeastPrivilegedMSGraph.psm1'

    # Version number of this module.
    ModuleVersion        = '1.0.0'

    # Supported PSEditions
    # CompatiblePSEditions = @()

    # ID used to uniquely identify this module
    GUID                 = 'a36f8f7d-ae1a-41d2-a957-cae8c22216aa'

    # Author of this module
    Author               = 'Morten Mynster'

    # Company or vendor of this module
    CompanyName          = 'Mynster'

    # Copyright statement for this module
    Copyright            = '(c) Morten Mynster. All rights reserved.'

    # Description of the functionality provided by this module
    Description          = 'Analyzes Microsoft Graph permissions and provides least privileged recommendations'

    # Minimum version of the PowerShell engine required by this module
    PowerShellVersion    = '5.0'

    # Name of the PowerShell host required by this module
    # PowerShellHostName = ''

    # Minimum version of the PowerShell host required by this module
    # PowerShellHostVersion = ''

    # Minimum version of Microsoft .NET Framework required by this module. This prerequisite is valid for the PowerShell Desktop edition only.
    # DotNetFrameworkVersion = ''

    # Minimum version of the common language runtime (CLR) required by this module. This prerequisite is valid for the PowerShell Desktop edition only.
    # ClrVersion = ''

    # Processor architecture (None, X86, Amd64) required by this module
    # ProcessorArchitecture = ''

    # Modules that must be imported into the global environment prior to importing this module
    RequiredModules      = @('EntraAuth', 'PSFramework')

    # Assemblies that must be loaded prior to importing this module
    # RequiredAssemblies = @()

    # Script files (.ps1) that are run in the caller's environment prior to importing this module.
    # ScriptsToProcess = @()

    # Type files (.ps1xml) to be loaded when importing this module
    # TypesToProcess = @()

    # Format files (.ps1xml) to be loaded when importing this module
    # FormatsToProcess = @()

    # Modules to import as nested modules of the module specified in RootModule/ModuleToProcess
    # NestedModules = @()

    # Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export.
    FunctionsToExport    = @('Export-PermissionAnalysisReport','Get-AppActivityData','Get-AppRoleAssignment','Get-AppThrottlingData','Get-PermissionAnalysis','Initialize-LogAnalyticsApi')

    # Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export.
    CmdletsToExport      = @()

    # Variables to export from this module
    VariablesToExport    = @()

    # Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export.
    AliasesToExport      = @()

    # DSC resources to export from this module
    DscResourcesToExport = @()

    # List of all modules packaged with this module
    # ModuleList = @()

    # List of all files packaged with this module
    FileList             = @(
        'data/permissions-v1.0.json',
        'data/permissions-beta.json',
        'data/base.html'
    )

    # Private data to pass to the module specified in RootModule/ModuleToProcess. This may also contain a PSData hashtable with additional module metadata used by PowerShell.
    PrivateData          = @{

        PSData = @{

            # Tags applied to this module. These help with module discovery in online galleries.
            # Tags = @()

            # A URL to the license for this module.
            # LicenseUri = ''

            # A URL to the main website for this project.
            # ProjectUri = ''

            # A URL to an icon representing this module.
            # IconUri = ''

            # ReleaseNotes of this module
            ReleaseNotes = '## [1.0.0] - 2025-12-15

### Added
- **PSFramework Integration:**
  - Utilizing the logging functionality along with runspace management
  - Provides significantly faster results (2x performance improvement even with the bug fix implemented)
- **GitHub Pages Documentation:**
  - Interactive command reference with searchable documentation
  - Modern dark-themed documentation site with responsive design
  - Comprehensive getting started guide
  - Workflow examples demonstrating common use cases
- **Get-AppActivityData:**
  - Introduce 3 new parameters
    - `-ThrottleLimit` allows you to specify a certain amoun of runspaces so it gathers multiple app data at once i recommend setting it somewhere between 5-20 the higher you go the more resources you use
    - `-MaxActivityEntries` This parameter allows you to specify how much data you want to base your analysis on lets say you want to look back 30 days but some apps might have sent 20 Millon requests in that time frame this parameter allows you to specify how many requests from the last 30 days you want to base of. This also allows you to speed up your analysis even further, usefull if you just want a fast overview but note that you might not get all endpoints that has been hit. Default amount is set to 100.000 request per app.
    - `-retainRawUri` Interested in the specific url''s your apps are hitting? well worry no further this switch allows you to retain the raw url instead of annomynizing it note that if you utilize this switch you will not be able to run a permission analysis on the endpoints

### Fixed
- **Critical bug in `Get-AppActivityData`:**
  - Applications with high activity volumes (e.g., 19 million requests) would fail to gather activity data and return 0 results
  - Command now splits datetime ranges to handle large datasets reliably
  - Results are now complete and accurate regardless of activity volume

### Performance
- 2x faster execution with PSFramework runspace implementation while maintaining complete data accuracy

### Acknowledgments
Huge thanks to @FriedrichWeinmann for his sparring and assistance on the PSFramework implementation.

'


            # Prerelease string of this module
            Prerelease   = ''

            # Flag to indicate whether the module requires explicit user acceptance for install/update/save
            # RequireLicenseAcceptance = $false

            # External dependent modules of this module
            # ExternalModuleDependencies = @()

        } # End of PSData hashtable

    } # End of PrivateData hashtable

    # HelpInfo URI of this module
    # HelpInfoURI = ''

    # Default prefix for commands exported from this module. Override the default prefix using Import-Module -Prefix.
    # DefaultCommandPrefix = ''

}