Omnicit.EntraRBAC

1.1.3-preview0007

Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.

Minimum PowerShell version

7.2

This is a prerelease version of Omnicit.EntraRBAC.
There is a newer prerelease version of this module available.
See the version list below for details.

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name Omnicit.EntraRBAC -RequiredVersion 1.1.3-preview0007 -AllowPrerelease

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name Omnicit.EntraRBAC -Version 1.1.3-preview0007 -Prerelease

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Omnicit AB

Package Details

Author(s)

  • Omnicit AB / Philip Haglund

Tags

EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS

Functions

Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure

PSEditions

Core

Dependencies

Release Notes

## [1.1.3-preview0007] - 2026-10-07

`Invoke-OERStructure` without `-TenantId`, and the builders that look up a name
(`New-OERAccessPackageApprovalStage`, `New-OERAccessPackageRequestorScope`,
`New-OERAccessReviewStage`), refuse with `SignInSuperseded` and send nothing when another command in
their pipeline signs in to another tenant or identity after they began; in a script block they begin
only when it runs, so name `-TenantId` there. Cmdlets a refused command calls are refused at their
own sign-in (`SignInRefused`), before any token request or prompt. A tenant named by domain is looked
up before any token request and each token checked against it: one from another tenant is refused
with `TenantMismatch`, a domain that names no tenant, or `common`, with the new
`TenantResolutionFailed`, and the warning after such a sign-in is gone. After a sign-in fails or is
refused, a command naming no tenant sends nothing (`SignInRefused`) until a sign-in naming its
tenant, `Connect-OER` or `Disconnect-OER` succeeds. An empty `-TenantId` is refused, by `Connect-OER`
with the new `InvalidTenantId`, and an Azure token no longer outlives a renewal from another tenant.

Sixteen cmdlets, such as `Remove-OERRoleAssignment` and `Set-OERRoleAssignment`, now warn before
the confirmation prompt rather than after it, so `-WhatIf` and `-Confirm` show the warning; with
`-WhatIf -WarningAction Stop` they stop at it instead of printing the What if line, changing
nothing. `Invoke-OERStructure -WhatIf` writes the warning of the cmdlet it would call for an
administrative unit's membership type change, a removed ABAC condition, a group PIM policy opened
for permanent eligibility and a reconciled MFA / authentication context pair; a real run now gives
that last one for a group's policy too.

Group member and owner reads include service principals, which Graph's v1.0 lists omit
(`Get-OERGroup -IncludeMembers -IncludeOwners`, `Get-OERGroupMember`, the inventory export,
`Invoke-OERStructure`); a failed read leaves the collection unread, not half-read. A document not
listing them reports them `Extra`, and `-Prune` leaves them in place. `-Prune` no longer removes, in
the run that creates a group, the unit membership its `administrativeUnit` gave it (`Skipped`,
`prune withheld`); every later apply with `-Prune` removes it unless the unit's `members` name the
group, which `Test-OERStructure` now also checks for a template-named group and a unit named by id.

`Set-OERGroupPimPolicy` puts back the accepted half of the MFA and authentication context pair when
Graph rejects the other, and neither it nor `Set-OERDirectoryRoleManagementPolicy` warns between its
first rule update and its last, so `-WarningAction Stop` no longer stops half-way. These two and
`Set-OERRoleManagementPolicy` refuse `-RequireApproval $false` beside an approver parameter
(`MutuallyExclusiveParameter`), and the last refuses an empty approver list (`ApproverRequired`); in
`Invoke-OERStructure` an empty Azure approver side matches an empty live one. Eleven cmdlets that
send a PIM schedule request treat an accepted request answered with a status starting `Failed` as an
error, after the request object (`EligibilityRequestFailed`, or the new `AssignmentRequestFailed`),
so `Invoke-OERStructure` reports the row Failed. `New-OERActiveRoleAssignment` opens a role policy
for a permanent assignment only once confirmed; it and `New-OEREligibleRoleAssignment` roll it back
if the assignment fails.

`Set-OERAccessPackageAssignmentPolicy` refuses a connected-organization scope that names none
(`InvalidPolicyInput`). `Remove-OERActiveDirectoryRoleAssignment` and
`Remove-OEREligibleDirectoryRoleAssignment`, refusing a piped `Get-OERGroupMember` row
(`NotDirectAssignment`), now say how to remove that principal's own assignment.

FileList

Version History

Version Downloads Last updated
1.1.4-previe... 4 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 3 10/9/2026
1.1.4-previe... 10 10/9/2026
1.1.4-previe... 5 10/9/2026
1.1.4-previe... 2 10/8/2026
1.1.4-previe... 0 10/8/2026
1.1.4-previe... 3 10/8/2026
1.1.4-previe... 4 10/7/2026
1.1.3 6 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... (current version) 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 4 10/7/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 5 10/6/2026
1.1.3-previe... 4 10/6/2026
1.1.2 6 10/6/2026
1.1.2-previe... 5 10/6/2026
1.1.2-previe... 5 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... 4 10/5/2026
1.1.2-previe... 5 10/4/2026
1.1.2-previe... 5 10/4/2026
1.1.1 8 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/3/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 4 10/2/2026
1.1.1-previe... 5 10/1/2026
1.1.0 23 10/1/2026
1.1.0-previe... 21 10/1/2026
1.1.0-previe... 4 9/30/2026
1.1.0-previe... 4 9/29/2026
1.1.0-previe... 4 9/28/2026
1.0.2-previe... 4 9/24/2026
1.0.2-previe... 4 9/23/2026
1.0.1 10 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 5 9/23/2026
1.0.0 8 9/18/2026
Show less