Omnicit.PIM
0.7.0-preview0001
Entra ID Privileged Identity Management (PIM) Self Activation Commands for Directory Roles, Azure Resources, and Entra ID Groups
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) Omnicit. All rights reserved.
Package Details
Author(s)
- Omnicit (originally by Justin Grote @justinwgrote)
Tags
PIM Azure EntraID Identity Privileged Windows MacOS Linux
Functions
Connect-OPIM Disable-OPIMAzureRole Disable-OPIMDirectoryRole Disable-OPIMEntraIDGroup Disable-OPIMMyRole Disconnect-OPIM Enable-OPIMAzureRole Enable-OPIMDirectoryRole Enable-OPIMEntraIDGroup Enable-OPIMMyRole Get-OPIMAzureRole Get-OPIMConfiguration Get-OPIMDirectoryRole Get-OPIMEntraIDGroup Install-OPIMConfiguration Remove-OPIMConfiguration Set-OPIMConfiguration Wait-OPIMDirectoryRole
PSEditions
Dependencies
-
- Az.Resources (>= 9.0.3)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [0.7.0-preview0001] - 2026-10-09
Each GitHub release of the module, and the version tag that marks it, now always points at the
commit whose build was published to the PowerShell Gallery. When the publish workflow cannot prove
which commit that is, it stops and says how to set the tag by hand, instead of tagging another
commit.
Azure roles (`Get-`, `Enable-` and `Disable-OPIMAzureRole`, and the Azure part of `pim` and `unpim`)
now sign in with AzAuth and send their requests themselves instead of through the Az modules'
commands. They need AzAuth 2.9.0 installed and PowerShell 7.4 or later; the module does not declare
AzAuth yet, and the Az modules stay listed as dependencies. The Azure sign-in, in the system browser
or with a device code, no longer reuses or ends an Az context of yours: a `Connect-AzAccount`
session is left alone. Its token must be for the Graph session's tenant and account, else
`TenantMismatch` or the new `AccountMismatch`, and nothing is sent. Output keeps its property names,
but Az's .NET type names are gone: a script that tested `-is` against an Az type checks
`$Obj.PSObject.TypeNames -contains 'Omnicit.PIM.AzureEligibilitySchedule'` (or another
`Omnicit.PIM.Azure*` name) instead. `Disconnect-OPIM` clears the module's Azure token, but not
AzAuth's own sign-in in the PowerShell process.
FileList
- Omnicit.PIM.nuspec
- Omnicit.PIM.psd1
- Formats\README.md
- en-US\about_Omnicit.PIM.help.txt
- Omnicit.PIM.psm1
- Formats\Omnicit.PIM.Types.ps1xml
- Formats\Omnicit.PIM.Format.ps1xml
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.7.0-previe... | 0 | 10/9/2026 |
| 0.7.0-previe... (current version) | 2 | 10/9/2026 |
| 0.6.1-previe... | 3 | 10/9/2026 |
| 0.6.1-previe... | 4 | 10/9/2026 |
| 0.6.0 | 6 | 10/9/2026 |
| 0.6.0-previe... | 8 | 10/8/2026 |
| 0.6.0-previe... | 3 | 10/8/2026 |
| 0.6.0-previe... | 3 | 10/8/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.5.2-previe... | 5 | 10/6/2026 |
| 0.5.2-previe... | 4 | 10/6/2026 |
| 0.5.1 | 85 | 5/29/2026 |
| 0.5.1-previe... | 4 | 5/29/2026 |
| 0.5.0 | 12 | 5/27/2026 |
| 0.5.0-previe... | 8 | 5/27/2026 |
| 0.5.0-previe... | 6 | 5/27/2026 |
| 0.4.0 | 20 | 4/21/2026 |
| 0.4.0-previe... | 7 | 4/21/2026 |
| 0.4.0-previe... | 4 | 4/20/2026 |
| 0.4.0-previe... | 5 | 4/19/2026 |
| 0.3.1 | 9 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 4 | 4/16/2026 |
| 0.3.0 | 5 | 4/16/2026 |
| 0.3.0-previe... | 13 | 4/15/2026 |
| 0.3.0-previe... | 7 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/13/2026 |
| 0.3.0-previe... | 5 | 4/2/2026 |
| 0.3.0-previe... | 3 | 4/2/2026 |