Omnicit.EntraRBAC.psd1

@{
    RootModule           = 'Omnicit.EntraRBAC.psm1'
    ModuleVersion        = '1.1.1'
    CompatiblePSEditions = @('Core')
    GUID                 = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42'
    Author               = 'Omnicit AB / Philip Haglund'
    CompanyName          = 'Omnicit'
    Copyright            = '(c) 2026 Omnicit AB'
    Description          = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.'
    PowerShellVersion    = '7.2'

    RequiredModules = @(
        @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' }
        @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' }
    )

    # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data).
    TypesToProcess   = @()
    FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml')

    FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure')
    CmdletsToExport   = @()
    VariablesToExport = @()
    AliasesToExport   = @()

    PrivateData = @{
        PSData = @{
            Tags                     = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance',
                                          'PSEdition_Core', 'Windows', 'Linux', 'MacOS')
            ProjectUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC'
            LicenseUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE'
            RequireLicenseAcceptance = $false
            ReleaseNotes             = '## [1.1.1-preview0005] - 2026-10-03

`Get-OERInventory` and `Export-OERInventory` write an access package''s unread resource role
bindings, or a catalog''s unread resources, as `"resourceRoles": null` or `"resources": null`, which
`schema.json` accepts and `Invoke-OERStructure` leaves untouched, and name the package or catalog in
`InventoryPartial`. Earlier versions wrote `[]`, which made `-Prune` remove every binding or
resource. `InventoryPartial` also reports a failed read of catalogs, their access packages and
assignment policies, and binding names; without those names a group''s binding is written under its
object id, as the catalog''s recorded name can belong to another group after a rename. Access
reviews refer to a package or policy by id when its name cannot be read (reported in
`InventoryPartial`) or when it is gone (unreported, without stray error records).

A refused, throttled or server-error read is now reported as such, not as a missing object, when
resolving a group, catalog, application or catalog resource name (no longer `GroupNotFound`,
`CatalogNotFound`, `ApplicationNotFound` or `CatalogResourceNotFound`), in the user, group, catalog
and assignment policy lookups of the approval, requestor and review cmdlets and the definition
lookup of `Remove-` and `Set-OERAccessReviewDefinition`, and for an unreadable Tenant Profile in
`Invoke-OERStructure`. Only a name matching nothing is not found. The five access review instance
cmdlets keep `AccessReviewDefinitionResolveFailed`, now a `ReadError` (was `ObjectNotFound`)
carrying the cause. `Add-OERGroupEligibility` no longer calls a group not onboarded when its policy
cannot be read, but proceeds, letting Graph enforce it. `Add-OERCatalogResource` adds nothing when
its existence check fails, and warns, returning nothing, if it cannot read back what it added.
Principal, PIM approver and Azure role definition lookups still report a failed read as
`PrincipalNotFound`, `ApproverNotFound` or `RoleDefinitionNotFound`.

An ambiguous name is now refused with `AmbiguousName`, naming the candidates, instead of using the
first match: an access review definition (`Remove-OERAccessReviewDefinition -DisplayName` could
delete, and `Set-OERAccessReviewDefinition` overwrite, another one), an access package''s assignment
policy, a catalog resource''s role (`Add-OERAccessPackageResourceRole`), and a subscription or
management group name in the Azure cmdlets (reported as `InvalidScope`, or
`ManagementGroupNotFound` by `Get-OERSubscription`, as a missing name is). `Invoke-OERStructure`
reports such an entry `Failed` and writes nothing for it; a binding whose resource name can match
several resources, or only a group outside the catalog, is `Failed` too, and the package''s binding
prune is withheld.

`Invoke-OERStructure -Prune` no longer removes an administrative unit''s scoped roles when directory
role names cannot be read: the unit is `Failed`, where earlier versions removed every scoped role
declared by name. Such a unit exports as `"scopedRoles": null`, named in `InventoryPartial`. Under
`-Prune` the engine also warns once, not twice, before removing a scoped role or Azure role
assignment.

`Invoke-OERStructure` now applies a PIM for Groups eligibility declared for a group the same run
creates. Until PIM for Groups knows a new group, Graph can answer its eligibility request with 404
`ResourceNotFound`, or accept the request and fail it; on the 404, earlier versions could fail with
many error records until a re-run. The engine waits both out within the same 30-second budget per
group it spends on the group''s PIM policy, so the wait itself leaves no error records; once the
budget is spent the row is `Failed`, saying a re-run usually applies it. A permanent eligibility
first waits likewise until the group''s policy is listed and readable; an existing group never waits.

'

            Prerelease               = 'preview0005'
        }
    }
}