Omnicit.EntraRBAC
1.1.3-preview0007
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.3-preview0007] - 2026-10-07
`Invoke-OERStructure` without `-TenantId`, and the builders that look up a name
(`New-OERAccessPackageApprovalStage`, `New-OERAccessPackageRequestorScope`,
`New-OERAccessReviewStage`), refuse with `SignInSuperseded` and send nothing when another command in
their pipeline signs in to another tenant or identity after they began; in a script block they begin
only when it runs, so name `-TenantId` there. Cmdlets a refused command calls are refused at their
own sign-in (`SignInRefused`), before any token request or prompt. A tenant named by domain is looked
up before any token request and each token checked against it: one from another tenant is refused
with `TenantMismatch`, a domain that names no tenant, or `common`, with the new
`TenantResolutionFailed`, and the warning after such a sign-in is gone. After a sign-in fails or is
refused, a command naming no tenant sends nothing (`SignInRefused`) until a sign-in naming its
tenant, `Connect-OER` or `Disconnect-OER` succeeds. An empty `-TenantId` is refused, by `Connect-OER`
with the new `InvalidTenantId`, and an Azure token no longer outlives a renewal from another tenant.
Sixteen cmdlets, such as `Remove-OERRoleAssignment` and `Set-OERRoleAssignment`, now warn before
the confirmation prompt rather than after it, so `-WhatIf` and `-Confirm` show the warning; with
`-WhatIf -WarningAction Stop` they stop at it instead of printing the What if line, changing
nothing. `Invoke-OERStructure -WhatIf` writes the warning of the cmdlet it would call for an
administrative unit's membership type change, a removed ABAC condition, a group PIM policy opened
for permanent eligibility and a reconciled MFA / authentication context pair; a real run now gives
that last one for a group's policy too.
Group member and owner reads include service principals, which Graph's v1.0 lists omit
(`Get-OERGroup -IncludeMembers -IncludeOwners`, `Get-OERGroupMember`, the inventory export,
`Invoke-OERStructure`); a failed read leaves the collection unread, not half-read. A document not
listing them reports them `Extra`, and `-Prune` leaves them in place. `-Prune` no longer removes, in
the run that creates a group, the unit membership its `administrativeUnit` gave it (`Skipped`,
`prune withheld`); every later apply with `-Prune` removes it unless the unit's `members` name the
group, which `Test-OERStructure` now also checks for a template-named group and a unit named by id.
`Set-OERGroupPimPolicy` puts back the accepted half of the MFA and authentication context pair when
Graph rejects the other, and neither it nor `Set-OERDirectoryRoleManagementPolicy` warns between its
first rule update and its last, so `-WarningAction Stop` no longer stops half-way. These two and
`Set-OERRoleManagementPolicy` refuse `-RequireApproval $false` beside an approver parameter
(`MutuallyExclusiveParameter`), and the last refuses an empty approver list (`ApproverRequired`); in
`Invoke-OERStructure` an empty Azure approver side matches an empty live one. Eleven cmdlets that
send a PIM schedule request treat an accepted request answered with a status starting `Failed` as an
error, after the request object (`EligibilityRequestFailed`, or the new `AssignmentRequestFailed`),
so `Invoke-OERStructure` reports the row Failed. `New-OERActiveRoleAssignment` opens a role policy
for a permanent assignment only once confirmed; it and `New-OEREligibleRoleAssignment` roll it back
if the assignment fails.
`Set-OERAccessPackageAssignmentPolicy` refuses a connected-organization scope that names none
(`InvalidPolicyInput`). `Remove-OERActiveDirectoryRoleAssignment` and
`Remove-OEREligibleDirectoryRoleAssignment`, refusing a piped `Get-OERGroupMember` row
(`NotDirectAssignment`), now say how to remove that principal's own assignment.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1