Omnicit.PIM
0.6.0-preview0004
Entra ID Privileged Identity Management (PIM) Self Activation Commands for Directory Roles, Azure Resources, and Entra ID Groups
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) Omnicit. All rights reserved.
Package Details
Author(s)
- Omnicit (originally by Justin Grote @justinwgrote)
Tags
PIM Azure EntraID Identity Privileged Windows MacOS Linux
Functions
Connect-OPIM Disable-OPIMAzureRole Disable-OPIMDirectoryRole Disable-OPIMEntraIDGroup Disable-OPIMMyRole Disconnect-OPIM Enable-OPIMAzureRole Enable-OPIMDirectoryRole Enable-OPIMEntraIDGroup Enable-OPIMMyRole Get-OPIMAzureRole Get-OPIMConfiguration Get-OPIMDirectoryRole Get-OPIMEntraIDGroup Install-OPIMConfiguration Remove-OPIMConfiguration Set-OPIMConfiguration Wait-OPIMDirectoryRole
PSEditions
Dependencies
-
- Az.Resources (>= 9.0.3)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [0.6.0-preview0004] - 2026-10-08
The module's source files are now plain ASCII without a byte-order mark. A few progress and confirmation messages and some help text show `--` and `->` where they used to show a typographic dash or arrow; apart from those characters, the ASCII change alters nothing about how the module behaves. `Get-Help about_Omnicit.PIM` now lists every command by area, and new automated checks keep the unit tests away from any real tenant and keep identifiers and credentials out of the documentation.
`Connect-OPIM`, `Enable-OPIMMyRole` and `Disable-OPIMMyRole` take a new `-DeviceCode` switch for machines without a browser, such as a remote session or a cloud PC: the command shows a short code and the address to open, and you finish the sign-in on any device. With `-IncludeARM`, Azure signs in with a device code too. Once used, every later sign-in in the same PowerShell session uses a device code until `Disconnect-OPIM`. Without the switch, sign-in is unchanged.
A session now stays on its tenant: a command that names none keeps the one you signed in to, a token for another tenant is refused (`TenantMismatch`), and Azure signs in to the same tenant, reuses an earlier Azure sign-in only for the same account, and asks for no subscription. The role, group and sign-in commands send nothing under a Microsoft Graph session another `Connect-MgGraph` started (`GraphSessionChanged`); run `Disconnect-OPIM`, which also disconnects that session, and sign in again. A command whose sign-in at its start was refused sends nothing more (`SignInRefused`), and a sign-in refused while a failed request is retried fails only that request; after a failed Azure sign-in (`AzureConnectFailed`) nothing is sent to Azure under an earlier one. `pim` and `unpim` stop when the Graph sign-in fails, and skip only Azure when the Azure sign-in fails unless the error preference is `Stop`. Errors from a failed Graph request or Azure role command no longer carry your sign-in token. Role and group lists read every page, a list that cannot be read is reported as that error instead of "not found", and `Wait-OPIMDirectoryRole` checks requests one after another (`-ThrottleLimit` has no effect).
A role or group can now be named by its display name, in the `Get-`, `Enable-` and `Disable-` commands: `Enable-OPIMDirectoryRole 'Usage Summary Reports Reader'`, `Enable-OPIMEntraIDGroup 'Finance Team' -AccessType Owner` (a group name means the membership by default) or `Enable-OPIMAzureRole 'Reader' -Scope <scope>`. The tab-completed form keeps working, and tab completion offers the bare name whenever it is unique. A name, or an `-Identity`, that matches more than one role is refused with the candidates (`AmbiguousName`) and nothing is activated or deactivated; for a role name on the `Enable-` and `Disable-` commands and on `Get-OPIMAzureRole`, `-Scope` picks one; otherwise the tab-completed form does. A name that matches nothing is `EligibleRoleNotFound`, and deactivating a role that is not active is `ActiveRoleNotFound`, which says so when the role is eligible but not active (already deactivated, or its activation has not finished yet) and names the active form when the role is active under another name; neither stops the command, and each name in a list is resolved on its own. `Get-OPIMAzureRole -RoleName` and `-Identity` now find roles below the root scope without extra rights, `-All -Scope` returns only the roles at that scope, and a `-Scope` ending in a slash is refused.
Requests now report their outcome: a failed or denied one is an error (`ActivationRequestFailed`), and one awaiting approval or still provisioning returns with a warning. `-Wait` stops after `-TimeoutSeconds` (300 by default, `ActivationWaitTimedOut`); an active role or group is not requested again. `-Activated` lists activations only; `unpim` refuses an entry matching several (`AmbiguousName`). `-Hours` is 1-24, `-NotBefore` works for Azure, and a time without an offset is local.
FileList
- Omnicit.PIM.nuspec
- Omnicit.PIM.psd1
- Formats\README.md
- en-US\about_Omnicit.PIM.help.txt
- Omnicit.PIM.psm1
- Formats\Omnicit.PIM.Types.ps1xml
- Formats\Omnicit.PIM.Format.ps1xml
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.7.0-previe... | 3 | 10/9/2026 |
| 0.7.0-previe... | 2 | 10/9/2026 |
| 0.6.1-previe... | 3 | 10/9/2026 |
| 0.6.1-previe... | 4 | 10/9/2026 |
| 0.6.0 | 6 | 10/9/2026 |
| 0.6.0-previe... | 8 | 10/8/2026 |
| 0.6.0-previe... (current version) | 3 | 10/8/2026 |
| 0.6.0-previe... | 3 | 10/8/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.5.2-previe... | 5 | 10/6/2026 |
| 0.5.2-previe... | 4 | 10/6/2026 |
| 0.5.1 | 85 | 5/29/2026 |
| 0.5.1-previe... | 4 | 5/29/2026 |
| 0.5.0 | 12 | 5/27/2026 |
| 0.5.0-previe... | 8 | 5/27/2026 |
| 0.5.0-previe... | 6 | 5/27/2026 |
| 0.4.0 | 20 | 4/21/2026 |
| 0.4.0-previe... | 7 | 4/21/2026 |
| 0.4.0-previe... | 4 | 4/20/2026 |
| 0.4.0-previe... | 5 | 4/19/2026 |
| 0.3.1 | 9 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 4 | 4/16/2026 |
| 0.3.0 | 5 | 4/16/2026 |
| 0.3.0-previe... | 13 | 4/15/2026 |
| 0.3.0-previe... | 7 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/13/2026 |
| 0.3.0-previe... | 5 | 4/2/2026 |
| 0.3.0-previe... | 3 | 4/2/2026 |