Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.1.2' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.1.2] - 2026-10-06 `Invoke-OERStructure` groups, matches and prunes `roleAssignments` on the resolved scope, ignoring case: entries spelling one subscription or management group scope differently no longer remove each other''s assignments on every `-Prune` run. A role given by GUID matches the live assignment at a resource group (`-Prune` removed and re-created it every run) and a management group. An unresolvable scope withholds the section''s prune, a second entry for one scope, principal and role is `Failed` and not written, and a failed read of a scope''s assignments is `Failed` and runs no prune there. A `roleAssignments` or `roleManagementPolicies` scope with a trailing `/` (other than `/`) or `//` is refused before anything is written. `Test-OERStructure` reports, and `Invoke-OERStructure` refuses, a document declaring the same group, administrative unit, catalog, access package within one catalog, access review, role assignment or role policy twice, ignoring case, or an empty or blank access package binding resource or role, catalog resource name, or the role or principal of an administrative unit scoped role. `Get-OERInventory` and `Export-OERInventory` leave out objects that share a name, naming them in `InventoryPartial`, which also reports an unreadable group, administrative unit or access review list or (export only) group roster; role assignment principals sharing a name are written by object id. An access package binding with an unreadable resource name is written by object id; with no id, the package''s `resourceRoles` is `null`, reported as partial. `Export-OERInventory`''s `README.md` lists what could not be read. `Invoke-OERStructure` no longer adds and then removes an administrative unit scoped role the directory role list does not name: a role declared by a name no live role of the principal matches is not added, the unnamed role is not removed, and the entry is `Skipped`. A role declared by template id or object id also matches a live scoped role carrying the other form (when the list names both the same), so it is neither re-added nor removed. `Add-OERGroupEligibility` writes `EligibilityRequestFailed` when Graph accepts the request but answers `Failed`, and `Invoke-OERStructure` reports it `Failed`, never `Updated`, for an existing group. `New-OERAccessPackageRequestorScope` accepts `AllExternalUsers`, `AllDirectoryServicePrincipals` and `AllDirectoryAgentIdentities`, so an exported policy with one is `Unchanged`; `SpecificDirectoryServicePrincipals` is refused (`InvalidPolicyInput`), and a policy Graph returns as `unknownFutureValue`, or an update that would drop connected organization targets, is `Failed` and writes nothing. In `Set-OERGroupPimPolicy`, `Set-OERDirectoryRoleManagementPolicy`, `Set-OERRoleManagementPolicy` and `Invoke-OERStructure`, an ambiguous approver name is `AmbiguousApproverName`, a failed lookup is reported as itself, and only a missing approver is `ApproverNotFound`. `New-OERAccessReviewDefinition` and `Invoke-OERStructure` report a failed read of the access package they derive the catalog from as itself (`CatalogDerivationFailed` stays for a package with no catalog). `Remove-OERAccessReviewDefinition` warns before confirmation if it cannot read the definition to check for a Lifecycle access review; a confirmed delete still happens. `Get-OERAccessReviewDefinition -IncludeInstances` gives `Instances` `$null` when unread. OER cmdlets send no Graph request once another `Connect-MgGraph` replaces the module''s Graph SDK session (`GraphSessionChanged`), and nothing when their sign-in fails or is refused (`SignInRefused`); `Connect-OER` connects again. Nothing is sent while a command runs whose sign-in another command in its pipeline later replaced with another tenant or identity (`SignInSuperseded`); run such commands as separate statements. `Connect-OER`''s help says a client secret reaches AzAuth as plain text and recommends a certificate or managed identity. ' Prerelease = '' } } } |