Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.1.1' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.1.1] - 2026-10-03 `Get-OERInventory` and `Export-OERInventory` write an access package''s unread resource role bindings, or a catalog''s unread resources, as `"resourceRoles": null` or `"resources": null`, which `schema.json` accepts and `Invoke-OERStructure` leaves untouched, and name the package or catalog in `InventoryPartial`. Earlier versions wrote `[]`, which made `-Prune` remove every binding or resource. `InventoryPartial` also reports a failed read of catalogs, their access packages and assignment policies, and binding names; without those names a group''s binding is written under its object id, as the catalog''s recorded name can belong to another group after a rename. Access reviews refer to a package or policy by id when its name cannot be read (reported in `InventoryPartial`) or when it is gone (unreported, without stray error records). A refused, throttled or server-error read is now reported as such, not as a missing object, when resolving a group, catalog, application or catalog resource name (no longer `GroupNotFound`, `CatalogNotFound`, `ApplicationNotFound` or `CatalogResourceNotFound`), in the user, group, catalog and assignment policy lookups of the approval, requestor and review cmdlets and the definition lookup of `Remove-` and `Set-OERAccessReviewDefinition`, and for an unreadable Tenant Profile in `Invoke-OERStructure`. Only a name matching nothing is not found. The five access review instance cmdlets keep `AccessReviewDefinitionResolveFailed`, now a `ReadError` (was `ObjectNotFound`) carrying the cause. `Add-OERGroupEligibility` no longer calls a group not onboarded when its policy cannot be read, but proceeds, letting Graph enforce it. `Add-OERCatalogResource` adds nothing when its existence check fails, and warns, returning nothing, if it cannot read back what it added. Principal, PIM approver and Azure role definition lookups still report a failed read as `PrincipalNotFound`, `ApproverNotFound` or `RoleDefinitionNotFound`. An ambiguous name is now refused with `AmbiguousName`, naming the candidates, instead of using the first match: an access review definition (`Remove-OERAccessReviewDefinition -DisplayName` could delete, and `Set-OERAccessReviewDefinition` overwrite, another one), an access package''s assignment policy, a catalog resource''s role (`Add-OERAccessPackageResourceRole`), and a subscription or management group name in the Azure cmdlets (reported as `InvalidScope`, or `ManagementGroupNotFound` by `Get-OERSubscription`, as a missing name is). `Invoke-OERStructure` reports such an entry `Failed` and writes nothing for it; a binding whose resource name can match several resources, or only a group outside the catalog, is `Failed` too, and the package''s binding prune is withheld. `Invoke-OERStructure -Prune` no longer removes an administrative unit''s scoped roles when directory role names cannot be read: the unit is `Failed`, where earlier versions removed every scoped role declared by name. Such a unit exports as `"scopedRoles": null`, named in `InventoryPartial`. Under `-Prune` the engine also warns once, not twice, before removing a scoped role or Azure role assignment. `Invoke-OERStructure` now applies a PIM for Groups eligibility declared for a group the same run creates. Until PIM for Groups knows a new group, Graph can answer its eligibility request with 404 `ResourceNotFound`, or accept the request and fail it; on the 404, earlier versions could fail with many error records until a re-run. The engine waits both out within the same 30-second budget per group it spends on the group''s PIM policy, so the wait itself leaves no error records; once the budget is spent the row is `Failed`, saying a re-run usually applies it. A permanent eligibility first waits likewise until the group''s policy is listed and readable; an existing group never waits. ' Prerelease = '' } } } |