Omnicit.EntraRBAC

1.1.0-preview0002

Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.

Minimum PowerShell version

7.2

This is a prerelease version of Omnicit.EntraRBAC.
There is a newer prerelease version of this module available.
See the version list below for details.

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name Omnicit.EntraRBAC -RequiredVersion 1.1.0-preview0002 -AllowPrerelease

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name Omnicit.EntraRBAC -Version 1.1.0-preview0002 -Prerelease

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Omnicit AB

Package Details

Author(s)

  • Omnicit AB / Philip Haglund

Tags

EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS

Functions

Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure

PSEditions

Core

Dependencies

Release Notes

## [1.1.0-preview0002] - 2026-09-29

`Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared
group member, owner or PIM eligibility, administrative unit member or scoped role, access package
resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and
the undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`,
with `prune withheld: declared entry '<entry>' could not be resolved`. Earlier versions could
delete them, PIM eligibility and Azure role assignments included. A service principal in
`roleAssignments` needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an
omitted `members`, `scopedRoles`, catalog `resources` or access package `resourceRoles` key, which
still prunes, and `-Prune` lists them before writing; set such a key to `null` to leave it alone.

PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`,
`-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and
`approvers { users[], groups[] }`, and `Get-OERInventory` exports them, `requireApproval` in every
`pimPolicy`. Approvers named by UPN or group name are resolved before comparison in every apply
section, so a re-run reports `Unchanged`; a `roleManagementPolicies` user approver must now be a
UPN or object id. Earlier versions could apply a group's owner settings, a permanent-eligibility
opening included, to its member policy while the owner policy was not yet listed: review the
member policies of groups onboarded by an apply run. A refused policy read is
`PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the same run gets up to
30 seconds for its policies to appear, a `404 ResourceNotFound` counting as not there yet.
`Test-OERStructure` warns about unknown keys in `groups` and `pimPolicy`, and
`Invoke-OERStructure` no longer returns an eligibility request among its results.

`Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a
directory role's PIM settings by role or policy id, Get also with `-All`. They return the Azure
cmdlets' `RoleManagementPolicy` object with `Scope` `/` and need no Azure token. Unlike
`Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group
approvers and vice versa, and an empty list clears that side. An MFA and authentication-context
pair the call does not touch is left alone. The apply section `directoryRoleManagementPolicies[]`
runs between access reviews and the Azure sections and is not yet exported. `-Role` tab-completes
built-in role names, and a delegated sign-in needs Privileged Role Administrator to change a
policy. `Get-OERRequiredScope` lists the least-privilege permissions of the new cmdlets, and
`RoleManagement.ReadWrite.Directory` for `Set-OERGroup`.

FileList

Version History

Version Downloads Last updated
1.1.1-previe... 3 10/2/2026
1.1.1-previe... 3 10/2/2026
1.1.1-previe... 5 10/1/2026
1.1.0 22 10/1/2026
1.1.0-previe... 21 10/1/2026
1.1.0-previe... 4 9/30/2026
1.1.0-previe... (current version) 3 9/29/2026
1.1.0-previe... 4 9/28/2026
1.0.2-previe... 4 9/24/2026
1.0.2-previe... 4 9/23/2026
1.0.1 10 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 5 9/23/2026
1.0.0 8 9/18/2026
Show less