Omnicit.PIM.psd1
|
# # Module manifest for module 'Omnicit.PIM' # # Generated by: Omnicit # # Generated on: 2026-03-25 # @{ # Script module or binary module file associated with this manifest. RootModule = 'Omnicit.PIM.psm1' # Version number of this module. ModuleVersion = '0.6.0' # Supported PSEditions CompatiblePSEditions = @('Core') # ID used to uniquely identify this module GUID = 'ed16ca8d-c9c0-4987-90b9-749edc96ebb8' # Author of this module Author = 'Omnicit (originally by Justin Grote @justinwgrote)' # Company or vendor of this module CompanyName = 'Omnicit' # Copyright statement for this module Copyright = '(c) Omnicit. All rights reserved.' # Description of the functionality provided by this module Description = 'Entra ID Privileged Identity Management (PIM) Self Activation Commands for Directory Roles, Azure Resources, and Entra ID Groups' # Minimum version of the PowerShell engine required by this module PowerShellVersion = '7.2' # Name of the PowerShell host required by this module # PowerShellHostName = '' # Minimum version of the PowerShell host required by this module # PowerShellHostVersion = '' # Minimum version of Microsoft .NET Framework required by this module. This prerequisite is valid for the PowerShell Desktop edition only. # DotNetFrameworkVersion = '' # Minimum version of the common language runtime (CLR) required by this module. This prerequisite is valid for the PowerShell Desktop edition only. # ClrVersion = '' # Processor architecture (None, X86, Amd64) required by this module # ProcessorArchitecture = '' # Modules that must be imported into the global environment prior to importing this module RequiredModules = @( @{ ModuleName = 'Az.Resources'; ModuleVersion = '9.0.3' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Assemblies that must be loaded prior to importing this module # RequiredAssemblies = @() # Script files (.ps1) that are run in the caller's environment prior to importing this module. # ScriptsToProcess = @() # Type files (.ps1xml) to be loaded when importing this module # Disabled: TypesToProcess re-registers type members on every Import-Module -Force but Remove-Module does NOT # clean type data, so the second test file import fails with "member is already present" errors. # Types are loaded via a single Update-TypeData -AppendPath call in the psm1 suffix instead. TypesToProcess = @() # Format files (.ps1xml) to be loaded when importing this module # Re-enabled: all format targets are Omnicit.PIM.* custom types (no Az-native type overrides), so # the AppendPath precedence issue with Az.Resources no longer applies. # The orphaned RoleAssignmentScheduleRequest override was removed because all Azure functions now # wrap output with Omnicit.PIM.AzureAssignmentScheduleRequest before returning. FormatsToProcess = @('Formats/Omnicit.PIM.Format.ps1xml') # Modules to import as nested modules of the module specified in RootModule/ModuleToProcess # NestedModules = @() # Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export. FunctionsToExport = @('Connect-OPIM','Disable-OPIMAzureRole','Disable-OPIMDirectoryRole','Disable-OPIMEntraIDGroup','Disable-OPIMMyRole','Disconnect-OPIM','Enable-OPIMAzureRole','Enable-OPIMDirectoryRole','Enable-OPIMEntraIDGroup','Enable-OPIMMyRole','Get-OPIMAzureRole','Get-OPIMConfiguration','Get-OPIMDirectoryRole','Get-OPIMEntraIDGroup','Install-OPIMConfiguration','Remove-OPIMConfiguration','Set-OPIMConfiguration','Wait-OPIMDirectoryRole') # Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export. CmdletsToExport = @() # Variables to export from this module VariablesToExport = @() # Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export. AliasesToExport = @('Connect-PIM','Disable-OPIMMyRoles','Disable-PIMADRole','Disable-PIMGroup','Disable-PIMResourceRole','Disable-PIMRole','Disconnect-PIM','Enable-OPIMMyRoles','Enable-PIMADRole','Enable-PIMGroup','Enable-PIMResourceRole','Enable-PIMRole','Get-PIMADRole','Get-PIMConfig','Get-PIMGroup','Get-PIMResourceRole','Get-PIMRole','pim','Remove-PIMConfig','unpim','Set-PIMConfig','Wait-PIMADRole','Wait-PIMRole') # DSC resources to export from this module DscResourcesToExport = @() # List of all modules packaged with this module # ModuleList = @() # List of all files packaged with this module # FileList = @() # Private data to pass to the module specified in RootModule/ModuleToProcess. This may also contain a PSData hashtable with additional module metadata used by PowerShell. PrivateData = @{ PSData = @{ # Tags applied to this module. These help with module discovery in online galleries. Tags = @('PIM', 'Azure', 'EntraID', 'Identity', 'Privileged', 'Windows', 'MacOS', 'Linux') # A URL to the license for this module. LicenseUri = 'https://github.com/Omnicit/Omnicit.PIM/LICENSE' # A URL to the main website for this project. ProjectUri = 'https://github.com/Omnicit/Omnicit.PIM' # A URL to an icon representing this module. IconUri = 'https://raw.githubusercontent.com/Omnicit/Omnicit.PIM/main/assets/icon.png' # ReleaseNotes of this module ReleaseNotes = '## [0.6.0] - 2026-10-09 Roles and groups can be named by display name, as `Enable-OPIMEntraIDGroup ''Finance Team'' -AccessType Owner` (a group name alone means membership), and completion offers the bare name when unique. A name or `-Identity` matching several is refused with the candidates (`AmbiguousName`) and nothing changes; `-Scope` (a role, where the command has it), `-AccessType` (a group) or the tab-completed form picks one. A name matching nothing is `EligibleRoleNotFound` (`ActiveRoleNotFound` when deactivating, saying if the role is only eligible or active under another name); neither stops the command or the next name. `Get-OPIMAzureRole -RoleName` and `-Identity` work below the root scope without extra rights, `-All -Scope` returns only that scope''s roles, and a `-Scope` ending in a slash is refused. A failed or denied request is an error (`ActivationRequestFailed`), and one awaiting approval or provisioning returns with a warning. `-Wait` stops after `-TimeoutSeconds` (default 300, `ActivationWaitTimedOut`); `Wait-OPIMDirectoryRole` checks requests in turn (`-ThrottleLimit` is ignored) and writes an expired one as `ActivationAlreadyExpired`. An active role or group is not requested again, `-Activated` lists activations only, `-Hours` is 1-24, `-NotBefore` works for Azure, and a time without an offset is local. Lists read every page; an unreadable list is its own error, not "not found", and a directory role whose administrative unit is unreadable is listed, with a warning, instead of ending the list. An ownership held as a group''s only owner cannot be deactivated and does not end: activate ownership only of a group with another owner. `pim` and `unpim` act on a directory role only at the scope its tenant map entry names (`roleDefinitionId|directoryScopeId`). An old entry, the role id alone, means `/` only and activates nothing for a role eligible only below it: pipe the alias''s directory roles to `Set-OPIMConfiguration` again. An active Azure role from `-Activated` is stored with its eligibility and its own scope; one activated at another scope than its eligibility is refused (`LinkedEligibilityNotFound`) or matches nothing. A 0.5.x module reading a 0.6.0 map acts on no directory role, or Azure role from `-Activated`, whose entry names a scope. `unpim` refuses an entry matching several (`AmbiguousName`). The map''s default path is `$HOME/.config/Omnicit.PIM/TenantMap.psd1` everywhere (unchanged on Windows), an apostrophe no longer breaks it, and `Set-OPIMConfiguration` keeps the tenant of an old string-form alias. `Install-OPIMConfiguration` without `-TenantId` takes its tenant only from the module''s own sign-in, or refuses (`TenantIdNotResolvable`). `-DeviceCode` on `Connect-OPIM`, `pim` and `unpim` signs in with a code entered on any device, for Azure too with `-IncludeARM`; the session keeps the mode until `Disconnect-OPIM`. A session stays on its tenant: a command naming none keeps it, a token for another is refused (`TenantMismatch`), and Azure signs in to it, reuses a sign-in only for the same account and asks for no subscription. Nothing is sent under a Graph session another `Connect-MgGraph` started (`GraphSessionChanged`): run `Disconnect-OPIM`, which also disconnects that session, and sign in again. A command whose sign-in was refused sends nothing more (`SignInRefused`), and after a failed Azure sign-in (`AzureConnectFailed`) nothing goes to Azure under an earlier one. `pim` and `unpim` stop if the Graph sign-in fails and skip only Azure if the Azure one does, unless the error preference is `Stop`. Errors from a failed Graph request or Azure role command no longer carry your sign-in token. Messages and help are ASCII (`--` and `->` mean a dash or arrow), and `Get-Help about_Omnicit.PIM` lists every command by area. ' # Prerelease string of this module Prerelease = '' # Flag to indicate whether the module requires explicit user acceptance for install/update/save # RequireLicenseAcceptance = $false # External dependent modules of this module # ExternalModuleDependencies = @() } # End of PSData hashtable } # End of PrivateData hashtable # HelpInfo URI of this module # HelpInfoURI = '' # Default prefix for commands exported from this module. Override the default prefix using Import-Module -Prefix. # DefaultCommandPrefix = '' } |