Omnicit.EntraRBAC
1.1.0-preview0002
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.0-preview0002] - 2026-09-29
`Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared
group member, owner or PIM eligibility, administrative unit member or scoped role, access package
resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and
the undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`,
with `prune withheld: declared entry '<entry>' could not be resolved`. Earlier versions could
delete them, PIM eligibility and Azure role assignments included. A service principal in
`roleAssignments` needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an
omitted `members`, `scopedRoles`, catalog `resources` or access package `resourceRoles` key, which
still prunes, and `-Prune` lists them before writing; set such a key to `null` to leave it alone.
PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`,
`-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and
`approvers { users[], groups[] }`, and `Get-OERInventory` exports them, `requireApproval` in every
`pimPolicy`. Approvers named by UPN or group name are resolved before comparison in every apply
section, so a re-run reports `Unchanged`; a `roleManagementPolicies` user approver must now be a
UPN or object id. Earlier versions could apply a group's owner settings, a permanent-eligibility
opening included, to its member policy while the owner policy was not yet listed: review the
member policies of groups onboarded by an apply run. A refused policy read is
`PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the same run gets up to
30 seconds for its policies to appear, a `404 ResourceNotFound` counting as not there yet.
`Test-OERStructure` warns about unknown keys in `groups` and `pimPolicy`, and
`Invoke-OERStructure` no longer returns an eligibility request among its results.
`Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a
directory role's PIM settings by role or policy id, Get also with `-All`. They return the Azure
cmdlets' `RoleManagementPolicy` object with `Scope` `/` and need no Azure token. Unlike
`Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group
approvers and vice versa, and an empty list clears that side. An MFA and authentication-context
pair the call does not touch is left alone. The apply section `directoryRoleManagementPolicies[]`
runs between access reviews and the Azure sections and is not yet exported. `-Role` tab-completes
built-in role names, and a delegated sign-in needs Privileged Role Administrator to change a
policy. `Get-OERRequiredScope` lists the least-privilege permissions of the new cmdlets, and
`RoleManagement.ReadWrite.Directory` for `Set-OERGroup`.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 5 | 10/1/2026 |
| 1.1.0 | 22 | 10/1/2026 |
| 1.1.0-previe... | 21 | 10/1/2026 |
| 1.1.0-previe... | 4 | 9/30/2026 |
| 1.1.0-previe... (current version) | 3 | 9/29/2026 |
| 1.1.0-previe... | 4 | 9/28/2026 |
| 1.0.2-previe... | 4 | 9/24/2026 |
| 1.0.2-previe... | 4 | 9/23/2026 |
| 1.0.1 | 10 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 5 | 9/23/2026 |
| 1.0.0 | 8 | 9/18/2026 |