Omnicit.EntraRBAC

1.1.1

Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.

Minimum PowerShell version

7.2

There is a newer prerelease version of this module available.
See the version list below for details.

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name Omnicit.EntraRBAC -RequiredVersion 1.1.1

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name Omnicit.EntraRBAC -Version 1.1.1

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Omnicit AB

Package Details

Author(s)

  • Omnicit AB / Philip Haglund

Tags

EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS

Functions

Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure

PSEditions

Core

Dependencies

Release Notes

## [1.1.1] - 2026-10-03

`Get-OERInventory` and `Export-OERInventory` write an access package's unread resource role
bindings, or a catalog's unread resources, as `"resourceRoles": null` or `"resources": null`, which
`schema.json` accepts and `Invoke-OERStructure` leaves untouched, and name the package or catalog in
`InventoryPartial`. Earlier versions wrote `[]`, which made `-Prune` remove every binding or
resource. `InventoryPartial` also reports a failed read of catalogs, their access packages and
assignment policies, and binding names; without those names a group's binding is written under its
object id, as the catalog's recorded name can belong to another group after a rename. Access
reviews refer to a package or policy by id when its name cannot be read (reported in
`InventoryPartial`) or when it is gone (unreported, without stray error records).

A refused, throttled or server-error read is now reported as such, not as a missing object, when
resolving a group, catalog, application or catalog resource name (no longer `GroupNotFound`,
`CatalogNotFound`, `ApplicationNotFound` or `CatalogResourceNotFound`), in the user, group, catalog
and assignment policy lookups of the approval, requestor and review cmdlets and the definition
lookup of `Remove-` and `Set-OERAccessReviewDefinition`, and for an unreadable Tenant Profile in
`Invoke-OERStructure`. Only a name matching nothing is not found. The five access review instance
cmdlets keep `AccessReviewDefinitionResolveFailed`, now a `ReadError` (was `ObjectNotFound`)
carrying the cause. `Add-OERGroupEligibility` no longer calls a group not onboarded when its policy
cannot be read, but proceeds, letting Graph enforce it. `Add-OERCatalogResource` adds nothing when
its existence check fails, and warns, returning nothing, if it cannot read back what it added.
Principal, PIM approver and Azure role definition lookups still report a failed read as
`PrincipalNotFound`, `ApproverNotFound` or `RoleDefinitionNotFound`.

An ambiguous name is now refused with `AmbiguousName`, naming the candidates, instead of using the
first match: an access review definition (`Remove-OERAccessReviewDefinition -DisplayName` could
delete, and `Set-OERAccessReviewDefinition` overwrite, another one), an access package's assignment
policy, a catalog resource's role (`Add-OERAccessPackageResourceRole`), and a subscription or
management group name in the Azure cmdlets (reported as `InvalidScope`, or
`ManagementGroupNotFound` by `Get-OERSubscription`, as a missing name is). `Invoke-OERStructure`
reports such an entry `Failed` and writes nothing for it; a binding whose resource name can match
several resources, or only a group outside the catalog, is `Failed` too, and the package's binding
prune is withheld.

`Invoke-OERStructure -Prune` no longer removes an administrative unit's scoped roles when directory
role names cannot be read: the unit is `Failed`, where earlier versions removed every scoped role
declared by name. Such a unit exports as `"scopedRoles": null`, named in `InventoryPartial`. Under
`-Prune` the engine also warns once, not twice, before removing a scoped role or Azure role
assignment.

`Invoke-OERStructure` now applies a PIM for Groups eligibility declared for a group the same run
creates. Until PIM for Groups knows a new group, Graph can answer its eligibility request with 404
`ResourceNotFound`, or accept the request and fail it; on the 404, earlier versions could fail with
many error records until a re-run. The engine waits both out within the same 30-second budget per
group it spends on the group's PIM policy, so the wait itself leaves no error records; once the
budget is spent the row is `Failed`, saying a re-run usually applies it. A permanent eligibility
first waits likewise until the group's policy is listed and readable; an existing group never waits.

FileList

Version History

Version Downloads Last updated
1.1.4-previe... 4 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 10 10/9/2026
1.1.4-previe... 5 10/9/2026
1.1.4-previe... 2 10/8/2026
1.1.4-previe... 0 10/8/2026
1.1.4-previe... 3 10/8/2026
1.1.4-previe... 4 10/7/2026
1.1.3 6 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 4 10/6/2026
1.1.2 6 10/6/2026
1.1.2-previe... 5 10/6/2026
1.1.2-previe... 5 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... 5 10/4/2026
1.1.2-previe... 5 10/4/2026
1.1.1 (current version) 8 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 5 10/1/2026
1.1.0 23 10/1/2026
1.1.0-previe... 21 10/1/2026
1.1.0-previe... 4 9/30/2026
1.1.0-previe... 4 9/29/2026
1.1.0-previe... 4 9/28/2026
1.0.2-previe... 4 9/24/2026
1.0.2-previe... 4 9/23/2026
1.0.1 10 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 5 9/23/2026
1.0.0 8 9/18/2026
Show less