Omnicit.EntraRBAC
1.1.2-preview0004
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.2-preview0004] - 2026-10-05
`Invoke-OERStructure` groups, matches and prunes `roleAssignments` on the resolved scope: every
spelling of one subscription or management group scope is one scope, compared case-insensitively;
earlier, two entries for one scope could remove each other's assignments on every `-Prune` run. A
role given by its GUID matches the live assignment at a resource group, where `-Prune` removed and
re-created it every run, and at a management group. An unresolvable scope withholds the section's
prune, and a repeat entry (same scope, principal and role) is `Failed` and not written. A failed
read of a scope's assignments is `Failed` and runs no prune there (earlier versions planned to
create assignments that exist). A `roleAssignments` or `roleManagementPolicies` scope with a
trailing `/` (other than `/`) or `//` is refused before anything is written.
`Test-OERStructure` reports, and `Invoke-OERStructure` refuses, a document that declares the same
group, administrative unit, catalog, access package within one catalog, access review, role
assignment or role policy twice, ignoring letter case, or an empty or blank access package binding
resource or role, catalog resource name, or the role or principal of an administrative unit scoped
role.
`Get-OERInventory` and `Export-OERInventory` leave out objects that share a name, naming them in
`InventoryPartial`, which also reports an unreadable group, administrative unit or access review
list or (for `Export-OERInventory`) group roster; role assignment principals that share a name are
written by object id. An access package binding whose resource name cannot be read is written by
object id; with no id, the package's `resourceRoles` is `null`, reported as partial.
`Export-OERInventory`'s bundle `README.md` lists everything it could not read.
`Invoke-OERStructure` no longer adds and then removes an administrative unit scoped role that the
directory role list does not name: for a role declared by name that no live role of the principal
matches, the role is not added, the unnamed role is not removed, and the entry is `Skipped`. A role
declared by its template id or object id also matches the live scoped role carrying the other id
form, when the directory role list names both the same, so it is neither added again nor removed.
`Add-OERGroupEligibility` writes `EligibilityRequestFailed` when Graph accepts an eligibility
request but answers `Failed`, and `Invoke-OERStructure` reports that request `Failed`, never
`Updated`, for an existing group. `New-OERAccessPackageRequestorScope` accepts `AllExternalUsers`,
`AllDirectoryServicePrincipals` and `AllDirectoryAgentIdentities`, so an exported policy with one is
`Unchanged`; `SpecificDirectoryServicePrincipals` is refused (`InvalidPolicyInput`), and a policy
Graph returns as `unknownFutureValue`, or an update that would drop connected organization targets,
is `Failed` and nothing is written.
In the three PIM policy cmdlets and `Invoke-OERStructure`, an ambiguous approver name is
`AmbiguousApproverName`, a failed lookup is reported as itself, and only a missing approver is
`ApproverNotFound`.
`New-OERAccessReviewDefinition` and `Invoke-OERStructure` report a failed read of the access package
made to derive its catalog as itself (`CatalogDerivationFailed` stays for a package with no
catalog). `Remove-OERAccessReviewDefinition` warns, before asking for confirmation, when it could
not read the definition to check for a Lifecycle access review; a confirmed delete still happens.
`Get-OERAccessReviewDefinition -IncludeInstances` gives `Instances` `$null` for unread instances.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1