Omnicit.EntraRBAC
1.1.4-preview0009
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.4-preview0009] - 2026-10-09
A permanent group eligibility grant refused after `Add-OERGroupEligibility` opened the group's PIM
policy now reports `PolicyOpenedButGrantFailed` first, naming the open policy, why the grant failed
and how to close it (`Set-OERGroupPimPolicy` with `-AllowPermanentEligibility:$false`; the old
advice left it open), even under `-ErrorAction Stop` and in `Invoke-OERStructure` results.
`Invoke-OERStructure`'s wait on a group it created now says, in `GroupNotOnboarded` and in a later
attempt's error, whether the policy was opened and, if so, how to close it. The Azure role
assignment cmdlets no longer report a rollback that finds nothing to change as failed; they ask for
a confirming read. No ErrorId changed.
`Disconnect-OER` now ends only the Graph SDK session the module connected and warns when it leaves
another. An Azure Resource Manager request without a token is refused (`ArmTokenAcquisitionFailed`),
not sent. `New-`/`Set-OERConfiguration` refuse a white-space `-TenantId`. `SignInSuperseded` names
its actual cause, and the `SignInRefused` after a failed sign-in no longer says the session may be
the previous tenant's.
Every device code sign-in now prints a new code, for Microsoft Graph and Azure Resource Manager
alike, so a later one in the same PowerShell session no longer reuses the credential AzAuth keeps
for the process, which could hang with no code shown, and needs no `-Force` to avoid that. The help
and README now say how a long run renews its token for each sign-in type and what it asks of you.
`Invoke-OERStructure -WhatIf` now plans what the run does when an Azure role policy entry's
approvers would name nobody: both report it `Failed` with `ApproverRequired` and change nothing.
`Test-OERStructure` refuses a `tenantId` that is not a string, as the schema does, or that ends in a
line break. The `NotDirectAssignment` example now parses for a role name with a curly apostrophe.
`SemiAnnually` (every six months) is a new access review cadence for `New-OERAccessReviewDefinition`,
`Set-OERAccessReviewDefinition` and a structure document's `recurrence`. A live six-month review now
exports as `SemiAnnually` without a warning and applies as `Unchanged`; older exports approximated
it as `Monthly`, so applying one skips the recurrence with a warning and leaves the review
semi-annual.
`Get-OERManagementGroup` now shows the parent of every listed group (the tenant root group has
none); a parent that cannot be read is reported as `ManagementGroupParentReadFailed`, not left
silently empty. A script that passes `-Expand` or `-Recurse` without `-Name` now fails at parameter
binding, or is asked for `-Name` where the host can prompt. An empty `-Name` is refused instead of
listing every group.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1