Omnicit.EntraRBAC.psd1

@{
    RootModule           = 'Omnicit.EntraRBAC.psm1'
    ModuleVersion        = '1.0.0'
    CompatiblePSEditions = @('Core')
    GUID                 = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42'
    Author               = 'Omnicit AB / Philip Haglund'
    CompanyName          = 'Omnicit'
    Copyright            = '(c) 2026 Omnicit AB'
    Description          = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.'
    PowerShellVersion    = '7.2'

    RequiredModules = @(
        @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' }
        @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' }
        @{ ModuleName = 'Az.Resources'; ModuleVersion = '9.0.3' }
    )

    # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data).
    TypesToProcess   = @()
    FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml')

    FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure')
    CmdletsToExport   = @()
    VariablesToExport = @()
    AliasesToExport   = @()

    PrivateData = @{
        PSData = @{
            Tags                     = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance',
                                          'PSEdition_Core', 'Windows', 'Linux', 'MacOS')
            ProjectUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC'
            LicenseUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE'
            RequireLicenseAcceptance = $false
            ReleaseNotes             = '## [1.0.0] - 2026-09-18

Omnicit.EntraRBAC 1.0.0 is the first public release. It manages Entra ID and Azure RBAC from
PowerShell 7.2+ on Windows, Linux and macOS, in the tenants you administer: groups and PIM for
Groups, Administrative Units, Entitlement Management, Access Reviews, Azure resources and role
assignments, and Azure PIM. A JSON inventory exports a tenant''s configuration, and a declarative
apply engine validates an edited document and converges the tenant to it.

Every state-changing cmdlet supports `-WhatIf` and `-Confirm`, and deleting a high-value object
prompts by default. Sign-in uses AzAuth for interactive, device code, client secret, certificate
and managed identity sessions, against the commercial cloud or the GCC High, DoD and China clouds.
Help examples use placeholder identifiers and addresses; substitute your own values before running them.

One PowerShell session works in one tenant at a time, and switching tenants inside a session is
limited by the sign-in type. A client secret sign-in for the same application cannot move to another
tenant until you run `Connect-OER -Force`, and a device code or managed identity sign-in does not
send the tenant you name: a device code token may come from the signed-in account''s own tenant
instead, and a managed identity token normally comes from the identity''s own tenant. The module
warns when it can see that a switch did not take effect, naming Azure Resource Manager calls,
including the ones that write role assignments, as affected alongside Microsoft Graph, and refuses a
token issued for another tenant outright when you name the tenant by its ID.

Known limitation: switching tenants by device code inside one session usually needs that same
`Connect-OER -Force` -- not every such switch is affected -- and without it the sign-in can stop
responding rather than fail: no device code appears, no error is raised, and only Ctrl+C ends the
call, after which the PowerShell session has to be exited. `-Force` cured it every time it was used,
and a new PowerShell session starts from a fresh credential.

Start with `README.md`, `Get-Help about_Omnicit.EntraRBAC`, and `Get-OERRequiredScope`, which
reports the Microsoft Graph permissions and Azure roles each cmdlet needs. Versions before 1.0.0
were never published; their history is kept in `CHANGELOG.md` in the project repository.

'

            Prerelease               = ''
        }
    }
}