Omnicit.EntraRBAC
1.0.0
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- Az.Resources (>= 9.0.3)
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.0.0] - 2026-09-18
Omnicit.EntraRBAC 1.0.0 is the first public release. It manages Entra ID and Azure RBAC from
PowerShell 7.2+ on Windows, Linux and macOS, in the tenants you administer: groups and PIM for
Groups, Administrative Units, Entitlement Management, Access Reviews, Azure resources and role
assignments, and Azure PIM. A JSON inventory exports a tenant's configuration, and a declarative
apply engine validates an edited document and converges the tenant to it.
Every state-changing cmdlet supports `-WhatIf` and `-Confirm`, and deleting a high-value object
prompts by default. Sign-in uses AzAuth for interactive, device code, client secret, certificate
and managed identity sessions, against the commercial cloud or the GCC High, DoD and China clouds.
Help examples use placeholder identifiers and addresses; substitute your own values before running them.
One PowerShell session works in one tenant at a time, and switching tenants inside a session is
limited by the sign-in type. A client secret sign-in for the same application cannot move to another
tenant until you run `Connect-OER -Force`, and a device code or managed identity sign-in does not
send the tenant you name: a device code token may come from the signed-in account's own tenant
instead, and a managed identity token normally comes from the identity's own tenant. The module
warns when it can see that a switch did not take effect, naming Azure Resource Manager calls,
including the ones that write role assignments, as affected alongside Microsoft Graph, and refuses a
token issued for another tenant outright when you name the tenant by its ID.
Known limitation: switching tenants by device code inside one session usually needs that same
`Connect-OER -Force` -- not every such switch is affected -- and without it the sign-in can stop
responding rather than fail: no device code appears, no error is raised, and only Ctrl+C ends the
call, after which the PowerShell session has to be exited. `-Force` cured it every time it was used,
and a new PowerShell session starts from a fresh credential.
Start with `README.md`, `Get-Help about_Omnicit.EntraRBAC`, and `Get-OERRequiredScope`, which
reports the Microsoft Graph permissions and Azure roles each cmdlet needs. Versions before 1.0.0
were never published; their history is kept in `CHANGELOG.md` in the project repository.
FileList
- Omnicit.EntraRBAC.nuspec
- en-US\about_Omnicit.EntraRBAC.help.txt
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- Omnicit.EntraRBAC.psm1
- Omnicit.EntraRBAC.psd1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 5 | 10/1/2026 |
| 1.1.0 | 22 | 10/1/2026 |
| 1.1.0-previe... | 21 | 10/1/2026 |
| 1.1.0-previe... | 4 | 9/30/2026 |
| 1.1.0-previe... | 3 | 9/29/2026 |
| 1.1.0-previe... | 4 | 9/28/2026 |
| 1.0.2-previe... | 4 | 9/24/2026 |
| 1.0.2-previe... | 4 | 9/23/2026 |
| 1.0.1 | 10 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 5 | 9/23/2026 |
| 1.0.0 (current version) | 8 | 9/18/2026 |