Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.0.0' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } @{ ModuleName = 'Az.Resources'; ModuleVersion = '9.0.3' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.0.0] - 2026-09-18 Omnicit.EntraRBAC 1.0.0 is the first public release. It manages Entra ID and Azure RBAC from PowerShell 7.2+ on Windows, Linux and macOS, in the tenants you administer: groups and PIM for Groups, Administrative Units, Entitlement Management, Access Reviews, Azure resources and role assignments, and Azure PIM. A JSON inventory exports a tenant''s configuration, and a declarative apply engine validates an edited document and converges the tenant to it. Every state-changing cmdlet supports `-WhatIf` and `-Confirm`, and deleting a high-value object prompts by default. Sign-in uses AzAuth for interactive, device code, client secret, certificate and managed identity sessions, against the commercial cloud or the GCC High, DoD and China clouds. Help examples use placeholder identifiers and addresses; substitute your own values before running them. One PowerShell session works in one tenant at a time, and switching tenants inside a session is limited by the sign-in type. A client secret sign-in for the same application cannot move to another tenant until you run `Connect-OER -Force`, and a device code or managed identity sign-in does not send the tenant you name: a device code token may come from the signed-in account''s own tenant instead, and a managed identity token normally comes from the identity''s own tenant. The module warns when it can see that a switch did not take effect, naming Azure Resource Manager calls, including the ones that write role assignments, as affected alongside Microsoft Graph, and refuses a token issued for another tenant outright when you name the tenant by its ID. Known limitation: switching tenants by device code inside one session usually needs that same `Connect-OER -Force` -- not every such switch is affected -- and without it the sign-in can stop responding rather than fail: no device code appears, no error is raised, and only Ctrl+C ends the call, after which the PowerShell session has to be exited. `-Force` cured it every time it was used, and a new PowerShell session starts from a fresh credential. Start with `README.md`, `Get-Help about_Omnicit.EntraRBAC`, and `Get-OERRequiredScope`, which reports the Microsoft Graph permissions and Azure roles each cmdlet needs. Versions before 1.0.0 were never published; their history is kept in `CHANGELOG.md` in the project repository. ' Prerelease = '' } } } |