Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.1.2' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.1.2-preview0003] - 2026-10-05 `Invoke-OERStructure` groups, matches and prunes `roleAssignments` on the scope it resolves, not on the text the document wrote. `sub:` and `subscription:` with an id, `/subscriptions/` with that id, the subscription''s name, and `mg:` with a management group''s name or display name and its path now name one scope, compared without regard to letter case. Earlier versions treated each spelling as its own scope, so under `-Prune` two entries for one scope could remove each other''s assignments on every run. A role given by its GUID now matches the live assignment at a resource group, where `-Prune` used to remove and re-create it on every run; it is matched on the GUID at a management group too. A scope that cannot be resolved withholds the prune of the whole `roleAssignments` section, and an entry that resolves to the same scope, principal and role as an earlier one is reported `Failed` and not written. A failed read of the assignments at a scope now reports the entry `Failed` with the read error, and no prune runs for that scope; earlier versions took the failed read for an empty list and planned to create assignments that exist. A `roleAssignments` or `roleManagementPolicies` scope written with a trailing `/` (other than `/` itself) or with `//` is now refused before anything is written, never read as another spelling of a scope. `Test-OERStructure` now reports, and `Invoke-OERStructure` refuses, a document that declares the same group, administrative unit, catalog, access package within one catalog, access review, role assignment, Azure role policy or directory role policy twice, compared without regard to letter case. `Get-OERInventory` and `Export-OERInventory` never write such a duplicate: objects that share a name are left out and named in `InventoryPartial`, and role assignment principals that share a name are written by object id. `Invoke-OERStructure` no longer adds and then removes an administrative unit scoped role whose name the directory role list does not give: when the document declares a role by name for the same principal and no live role of that principal matches it, the declared role is not added, the unnamed role is not removed, and the entry is reported `Skipped`, since the unnamed role may be the declared one. Declaring the role by its id reconciles it. `Get-OERInventory` and `Export-OERInventory` now report a group, administrative unit or access review list that could not be read at all through `InventoryPartial`, and `Export-OERInventory` a group roster that could not be read; such a section is still written as an empty array. An access package binding whose resource name cannot be read is written by the group''s or application''s object id, and when there is no such id the package''s `resourceRoles` are written as `null` and reported as partial. `Test-OERStructure` now reports, and `Invoke-OERStructure` refuses, an empty or blank access package binding resource or role, catalog resource name, or administrative unit scoped role or principal. A scoped role declared by its role id now also matches a live scoped role that the directory role list names the same, so a role declared by its role template id is neither added again nor removed when the live scoped role carries the role''s object id, or the other way round. `Export-OERInventory` now lists in the bundle''s `README.md` everything it could not read, or states that it read everything. ' Prerelease = 'preview0003' } } } |