Omnicit.EntraRBAC
1.1.1-preview0005
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.1-preview0005] - 2026-10-03
`Get-OERInventory` and `Export-OERInventory` write an access package's unread resource role
bindings, or a catalog's unread resources, as `"resourceRoles": null` or `"resources": null`, which
`schema.json` accepts and `Invoke-OERStructure` leaves untouched, and name the package or catalog in
`InventoryPartial`. Earlier versions wrote `[]`, which made `-Prune` remove every binding or
resource. `InventoryPartial` also reports a failed read of catalogs, their access packages and
assignment policies, and binding names; without those names a group's binding is written under its
object id, as the catalog's recorded name can belong to another group after a rename. Access
reviews refer to a package or policy by id when its name cannot be read (reported in
`InventoryPartial`) or when it is gone (unreported, without stray error records).
A refused, throttled or server-error read is now reported as such, not as a missing object, when
resolving a group, catalog, application or catalog resource name (no longer `GroupNotFound`,
`CatalogNotFound`, `ApplicationNotFound` or `CatalogResourceNotFound`), in the user, group, catalog
and assignment policy lookups of the approval, requestor and review cmdlets and the definition
lookup of `Remove-` and `Set-OERAccessReviewDefinition`, and for an unreadable Tenant Profile in
`Invoke-OERStructure`. Only a name matching nothing is not found. The five access review instance
cmdlets keep `AccessReviewDefinitionResolveFailed`, now a `ReadError` (was `ObjectNotFound`)
carrying the cause. `Add-OERGroupEligibility` no longer calls a group not onboarded when its policy
cannot be read, but proceeds, letting Graph enforce it. `Add-OERCatalogResource` adds nothing when
its existence check fails, and warns, returning nothing, if it cannot read back what it added.
Principal, PIM approver and Azure role definition lookups still report a failed read as
`PrincipalNotFound`, `ApproverNotFound` or `RoleDefinitionNotFound`.
An ambiguous name is now refused with `AmbiguousName`, naming the candidates, instead of using the
first match: an access review definition (`Remove-OERAccessReviewDefinition -DisplayName` could
delete, and `Set-OERAccessReviewDefinition` overwrite, another one), an access package's assignment
policy, a catalog resource's role (`Add-OERAccessPackageResourceRole`), and a subscription or
management group name in the Azure cmdlets (reported as `InvalidScope`, or
`ManagementGroupNotFound` by `Get-OERSubscription`, as a missing name is). `Invoke-OERStructure`
reports such an entry `Failed` and writes nothing for it; a binding whose resource name can match
several resources, or only a group outside the catalog, is `Failed` too, and the package's binding
prune is withheld.
`Invoke-OERStructure -Prune` no longer removes an administrative unit's scoped roles when directory
role names cannot be read: the unit is `Failed`, where earlier versions removed every scoped role
declared by name. Such a unit exports as `"scopedRoles": null`, named in `InventoryPartial`. Under
`-Prune` the engine also warns once, not twice, before removing a scoped role or Azure role
assignment.
`Invoke-OERStructure` now applies a PIM for Groups eligibility declared for a group the same run
creates. Until PIM for Groups knows a new group, Graph can answer its eligibility request with 404
`ResourceNotFound`, or accept the request and fail it; on the 404, earlier versions could fail with
many error records until a re-run. The engine waits both out within the same 30-second budget per
group it spends on the group's PIM policy, so the wait itself leaves no error records; once the
budget is spent the row is `Failed`, saying a re-run usually applies it. A permanent eligibility
first waits likewise until the group's policy is listed and readable; an existing group never waits.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1