Omnicit.EntraRBAC

1.1.2-preview0002

Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.

Minimum PowerShell version

7.2

This is a prerelease version of Omnicit.EntraRBAC.
There is a newer prerelease version of this module available.
See the version list below for details.

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name Omnicit.EntraRBAC -RequiredVersion 1.1.2-preview0002 -AllowPrerelease

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name Omnicit.EntraRBAC -Version 1.1.2-preview0002 -Prerelease

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Omnicit AB

Package Details

Author(s)

  • Omnicit AB / Philip Haglund

Tags

EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS

Functions

Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure

PSEditions

Core

Dependencies

Release Notes

## [1.1.2-preview0002] - 2026-10-04

`Invoke-OERStructure` groups, matches and prunes `roleAssignments` on the scope it resolves,
not on the text the document wrote. `sub:` and `subscription:` with an id, `/subscriptions/` with
that id, the subscription's name, and `mg:` with a management group's name or display name and its
path now name one scope, compared without regard to letter case. Earlier versions treated each
spelling as its own scope, so under `-Prune` two entries for one scope could remove each other's
assignments on every run. A role given by its GUID now matches the live assignment at a resource
group, where `-Prune` used to remove and re-create it on every run; it is matched on the GUID at a
management group too. A scope that cannot be resolved withholds the prune of the whole
`roleAssignments` section, and an entry that resolves to the same scope, principal and role as an
earlier one is reported `Failed` and not written. A failed read of the assignments at a scope now
reports the entry `Failed` with the read error, and no prune runs for that scope; earlier versions
took the failed read for an empty list and planned to create assignments that exist. A
`roleAssignments` or `roleManagementPolicies` scope written with a trailing `/` (other than `/`
itself) or with `//` is now refused before anything is written, never read as another spelling of a
scope.

`Test-OERStructure` now reports, and `Invoke-OERStructure` refuses, a document that declares the
same group, administrative unit, catalog, access package within one catalog, access review, role
assignment, Azure role policy or directory role policy twice, compared without regard to letter case.
`Get-OERInventory` and `Export-OERInventory` never write such a duplicate: objects that share a
name are left out and named in `InventoryPartial`, and role assignment principals that share a
name are written by object id.

FileList

Version History

Version Downloads Last updated
1.1.4-previe... 4 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 10 10/9/2026
1.1.4-previe... 5 10/9/2026
1.1.4-previe... 2 10/8/2026
1.1.4-previe... 0 10/8/2026
1.1.4-previe... 3 10/8/2026
1.1.4-previe... 4 10/7/2026
1.1.3 6 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 4 10/6/2026
1.1.2 6 10/6/2026
1.1.2-previe... 5 10/6/2026
1.1.2-previe... 5 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... (current version) 5 10/4/2026
1.1.2-previe... 5 10/4/2026
1.1.1 8 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 5 10/1/2026
1.1.0 23 10/1/2026
1.1.0-previe... 21 10/1/2026
1.1.0-previe... 4 9/30/2026
1.1.0-previe... 4 9/29/2026
1.1.0-previe... 4 9/28/2026
1.0.2-previe... 4 9/24/2026
1.0.2-previe... 4 9/23/2026
1.0.1 10 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 5 9/23/2026
1.0.0 8 9/18/2026
Show less