Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.1.4' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.1.4-preview0009] - 2026-10-09 A permanent group eligibility grant refused after `Add-OERGroupEligibility` opened the group''s PIM policy now reports `PolicyOpenedButGrantFailed` first, naming the open policy, why the grant failed and how to close it (`Set-OERGroupPimPolicy` with `-AllowPermanentEligibility:$false`; the old advice left it open), even under `-ErrorAction Stop` and in `Invoke-OERStructure` results. `Invoke-OERStructure`''s wait on a group it created now says, in `GroupNotOnboarded` and in a later attempt''s error, whether the policy was opened and, if so, how to close it. The Azure role assignment cmdlets no longer report a rollback that finds nothing to change as failed; they ask for a confirming read. No ErrorId changed. `Disconnect-OER` now ends only the Graph SDK session the module connected and warns when it leaves another. An Azure Resource Manager request without a token is refused (`ArmTokenAcquisitionFailed`), not sent. `New-`/`Set-OERConfiguration` refuse a white-space `-TenantId`. `SignInSuperseded` names its actual cause, and the `SignInRefused` after a failed sign-in no longer says the session may be the previous tenant''s. Every device code sign-in now prints a new code, for Microsoft Graph and Azure Resource Manager alike, so a later one in the same PowerShell session no longer reuses the credential AzAuth keeps for the process, which could hang with no code shown, and needs no `-Force` to avoid that. The help and README now say how a long run renews its token for each sign-in type and what it asks of you. `Invoke-OERStructure -WhatIf` now plans what the run does when an Azure role policy entry''s approvers would name nobody: both report it `Failed` with `ApproverRequired` and change nothing. `Test-OERStructure` refuses a `tenantId` that is not a string, as the schema does, or that ends in a line break. The `NotDirectAssignment` example now parses for a role name with a curly apostrophe. `SemiAnnually` (every six months) is a new access review cadence for `New-OERAccessReviewDefinition`, `Set-OERAccessReviewDefinition` and a structure document''s `recurrence`. A live six-month review now exports as `SemiAnnually` without a warning and applies as `Unchanged`; older exports approximated it as `Monthly`, so applying one skips the recurrence with a warning and leaves the review semi-annual. `Get-OERManagementGroup` now shows the parent of every listed group (the tenant root group has none); a parent that cannot be read is reported as `ManagementGroupParentReadFailed`, not left silently empty. A script that passes `-Expand` or `-Recurse` without `-Name` now fails at parameter binding, or is asked for `-Name` where the host can prompt. An empty `-Name` is refused instead of listing every group. ' Prerelease = 'preview0009' } } } |