Omnicit.EntraRBAC
1.1.4-preview0006
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.4-preview0006] - 2026-10-09
A permanent group eligibility grant refused after `Add-OERGroupEligibility` opened the group's PIM
policy now reports `PolicyOpenedButGrantFailed` first, naming the open policy, why the grant failed
and how to close it (`Set-OERGroupPimPolicy` with `-AllowPermanentEligibility:$false`; the old
advice left it open), even under `-ErrorAction Stop` and in `Invoke-OERStructure` results.
`Invoke-OERStructure`'s wait on a group it created now says, in `GroupNotOnboarded` and in a later
attempt's error, whether the policy was opened and, if so, how to close it. The Azure role
assignment cmdlets no longer report a rollback that finds nothing to change as failed; they ask for
a confirming read. No ErrorId changed.
`Disconnect-OER` now ends only the Graph SDK session the module connected and warns when it leaves
another. An Azure Resource Manager request without a token is refused (`ArmTokenAcquisitionFailed`),
not sent. `New-`/`Set-OERConfiguration` refuse a white-space `-TenantId`. `SignInSuperseded` names
its actual cause, and the `SignInRefused` after a failed sign-in no longer says the session may be
the previous tenant's.
`Invoke-OERStructure -WhatIf` now plans what the run does when an Azure role policy entry's
approvers would name nobody: both report it `Failed` with `ApproverRequired` and change nothing.
`Test-OERStructure` refuses a `tenantId` that is not a string, as the schema does, or that ends in a
line break. The `NotDirectAssignment` example now parses for a role name with a curly apostrophe.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psm1
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt