Omnicit.PIM
0.7.0-preview0002
Entra ID Privileged Identity Management (PIM) Self Activation Commands for Directory Roles, Azure Resources, and Entra ID Groups
Minimum PowerShell version
7.4
Installation Options
Owners
Copyright
(c) Omnicit. All rights reserved.
Package Details
Author(s)
- Omnicit (originally by Justin Grote @justinwgrote)
Tags
PIM Azure EntraID Identity Privileged Windows MacOS Linux
Functions
Connect-OPIM Disable-OPIMAzureRole Disable-OPIMDirectoryRole Disable-OPIMEntraIDGroup Disable-OPIMMyRole Disconnect-OPIM Enable-OPIMAzureRole Enable-OPIMDirectoryRole Enable-OPIMEntraIDGroup Enable-OPIMMyRole Get-OPIMAzureRole Get-OPIMConfiguration Get-OPIMDirectoryRole Get-OPIMEntraIDGroup Install-OPIMConfiguration Remove-OPIMConfiguration Set-OPIMConfiguration Wait-OPIMDirectoryRole
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [0.7.0-preview0002] - 2026-10-09
Each GitHub release of the module, and the version tag that marks it, now always points at the
commit whose build was published to the PowerShell Gallery. When the publish workflow cannot prove
which commit that is, it stops and says how to set the tag by hand, instead of tagging another
commit.
Azure roles (`Get-`, `Enable-` and `Disable-OPIMAzureRole`, and the Azure part of `pim` and `unpim`)
now sign in with AzAuth and send their requests themselves instead of through the Az modules'
commands. The Azure sign-in, in the system browser or with a device code, no longer reuses or ends
an Az context of yours: a `Connect-AzAccount` session is left alone. Its token must be for the Graph
session's tenant and account, else `TenantMismatch` or the new `AccountMismatch`, and nothing is
sent. Output keeps its property names, but Az's .NET type names are gone: a script that tested `-is`
against an Az type checks `$Obj.PSObject.TypeNames -contains 'Omnicit.PIM.AzureEligibilitySchedule'`
(or another `Omnicit.PIM.Azure*` name) instead. `Disconnect-OPIM` clears the module's Azure token,
but not AzAuth's own sign-in in the PowerShell process.
Omnicit.PIM no longer depends on the Az modules. Installing it brings AzAuth (2.9.0 or later) and
Microsoft.Graph.Authentication instead of Az.Resources and Az.Accounts, and importing it loads no Az
module. A script that used an Az.Resources or Az.Accounts command only because this module brought
it along must now install and import that module itself. The module now requires PowerShell 7.4 or
later, which AzAuth needs: on PowerShell 7.2 or 7.3 it no longer imports.
FileList
- Omnicit.PIM.nuspec
- Omnicit.PIM.psd1
- Formats\README.md
- en-US\about_Omnicit.PIM.help.txt
- Omnicit.PIM.psm1
- Formats\Omnicit.PIM.Types.ps1xml
- Formats\Omnicit.PIM.Format.ps1xml
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.7.0-previe... (current version) | 3 | 10/9/2026 |
| 0.7.0-previe... | 2 | 10/9/2026 |
| 0.6.1-previe... | 3 | 10/9/2026 |
| 0.6.1-previe... | 4 | 10/9/2026 |
| 0.6.0 | 6 | 10/9/2026 |
| 0.6.0-previe... | 8 | 10/8/2026 |
| 0.6.0-previe... | 3 | 10/8/2026 |
| 0.6.0-previe... | 3 | 10/8/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.6.0-previe... | 4 | 10/7/2026 |
| 0.5.2-previe... | 5 | 10/6/2026 |
| 0.5.2-previe... | 4 | 10/6/2026 |
| 0.5.1 | 85 | 5/29/2026 |
| 0.5.1-previe... | 4 | 5/29/2026 |
| 0.5.0 | 12 | 5/27/2026 |
| 0.5.0-previe... | 8 | 5/27/2026 |
| 0.5.0-previe... | 6 | 5/27/2026 |
| 0.4.0 | 20 | 4/21/2026 |
| 0.4.0-previe... | 7 | 4/21/2026 |
| 0.4.0-previe... | 4 | 4/20/2026 |
| 0.4.0-previe... | 5 | 4/19/2026 |
| 0.3.1 | 9 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 3 | 4/16/2026 |
| 0.3.1-previe... | 4 | 4/16/2026 |
| 0.3.0 | 5 | 4/16/2026 |
| 0.3.0-previe... | 13 | 4/15/2026 |
| 0.3.0-previe... | 7 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/14/2026 |
| 0.3.0-previe... | 3 | 4/13/2026 |
| 0.3.0-previe... | 5 | 4/2/2026 |
| 0.3.0-previe... | 3 | 4/2/2026 |