Omnicit.EntraRBAC.psd1

@{
    RootModule           = 'Omnicit.EntraRBAC.psm1'
    ModuleVersion        = '1.1.4'
    CompatiblePSEditions = @('Core')
    GUID                 = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42'
    Author               = 'Omnicit AB / Philip Haglund'
    CompanyName          = 'Omnicit'
    Copyright            = '(c) 2026 Omnicit AB'
    Description          = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.'
    PowerShellVersion    = '7.2'

    RequiredModules = @(
        @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' }
        @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' }
    )

    # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data).
    TypesToProcess   = @()
    FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml')

    FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure')
    CmdletsToExport   = @()
    VariablesToExport = @()
    AliasesToExport   = @()

    PrivateData = @{
        PSData = @{
            Tags                     = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance',
                                          'PSEdition_Core', 'Windows', 'Linux', 'MacOS')
            ProjectUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC'
            LicenseUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE'
            RequireLicenseAcceptance = $false
            ReleaseNotes             = '## [1.1.4-preview0010] - 2026-10-09

A permanent group eligibility grant refused after `Add-OERGroupEligibility` opened the group''s PIM
policy now reports `PolicyOpenedButGrantFailed` first, naming the open policy, why the grant failed
and how to close it (`Set-OERGroupPimPolicy` with `-AllowPermanentEligibility:$false`; the old
advice left it open), even under `-ErrorAction Stop` and in `Invoke-OERStructure` results.
`Invoke-OERStructure`''s wait on a group it created now says, in `GroupNotOnboarded` and in a later
attempt''s error, whether the policy was opened and, if so, how to close it. The Azure role
assignment cmdlets no longer report a rollback that finds nothing to change as failed; they ask for
a confirming read. No ErrorId changed.

`Disconnect-OER` now ends only the Graph SDK session the module connected and warns when it leaves
another. An Azure Resource Manager request without a token is refused (`ArmTokenAcquisitionFailed`),
not sent. `New-`/`Set-OERConfiguration` refuse a white-space `-TenantId`. `SignInSuperseded` names
its actual cause, and the `SignInRefused` after a failed sign-in no longer says the session may be
the previous tenant''s.

Every device code sign-in now prints a new code, for Microsoft Graph and Azure Resource Manager
alike, so a later one in the same PowerShell session no longer reuses the credential AzAuth keeps
for the process, which could hang with no code shown, and needs no `-Force` to avoid that. The help
and README now say how a long run renews its token for each sign-in type and what it asks of you.

`Invoke-OERStructure -WhatIf` now plans what the run does when an Azure role policy entry''s
approvers would name nobody: both report it `Failed` with `ApproverRequired` and change nothing.
`Test-OERStructure` refuses a `tenantId` that is not a string, as the schema does, or that ends in a
line break. The `NotDirectAssignment` example now parses for a role name with a curly apostrophe.

`SemiAnnually` (every six months) is a new access review cadence for `New-OERAccessReviewDefinition`,
`Set-OERAccessReviewDefinition` and a structure document''s `recurrence`. A live six-month review now
exports as `SemiAnnually` without a warning and applies as `Unchanged`; older exports approximated
it as `Monthly`, so applying one skips the recurrence with a warning and leaves the review
semi-annual.

`Get-OERManagementGroup` now shows the parent of every listed group (the tenant root group has
none); a parent that cannot be read is reported as `ManagementGroupParentReadFailed`, not left
silently empty. A script that passes `-Expand` or `-Recurse` without `-Name` now fails at parameter
binding, or is asked for `-Name` where the host can prompt. An empty `-Name` is refused instead of
listing every group.

`Get-OERGroup` now shows `OnPremisesSyncEnabled`, in its table too. `groupsRoster.json` marks every
group `onPremisesSynced`, and `Export-OERInventory -IncludeSyncedGroups` keeps the synchronized
security groups in full detail in `inventory.json`, where they carry `onPremisesSynced: true`.
`Invoke-OERStructure` writes nothing to a synchronized group: each change is reported `Skipped`, with
one warning per group, and `-Prune` leaves it untouched.

'

            Prerelease               = 'preview0010'
        }
    }
}