Omnicit.EntraRBAC.psd1

@{
    RootModule           = 'Omnicit.EntraRBAC.psm1'
    ModuleVersion        = '1.1.0'
    CompatiblePSEditions = @('Core')
    GUID                 = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42'
    Author               = 'Omnicit AB / Philip Haglund'
    CompanyName          = 'Omnicit'
    Copyright            = '(c) 2026 Omnicit AB'
    Description          = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.'
    PowerShellVersion    = '7.2'

    RequiredModules = @(
        @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' }
        @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' }
    )

    # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data).
    TypesToProcess   = @()
    FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml')

    FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure')
    CmdletsToExport   = @()
    VariablesToExport = @()
    AliasesToExport   = @()

    PrivateData = @{
        PSData = @{
            Tags                     = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance',
                                          'PSEdition_Core', 'Windows', 'Linux', 'MacOS')
            ProjectUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC'
            LicenseUri               = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE'
            RequireLicenseAcceptance = $false
            ReleaseNotes             = '## [1.1.0-preview0002] - 2026-09-29

`Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared
group member, owner or PIM eligibility, administrative unit member or scoped role, access package
resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and
the undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`,
with `prune withheld: declared entry ''<entry>'' could not be resolved`. Earlier versions could
delete them, PIM eligibility and Azure role assignments included. A service principal in
`roleAssignments` needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an
omitted `members`, `scopedRoles`, catalog `resources` or access package `resourceRoles` key, which
still prunes, and `-Prune` lists them before writing; set such a key to `null` to leave it alone.

PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`,
`-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and
`approvers { users[], groups[] }`, and `Get-OERInventory` exports them, `requireApproval` in every
`pimPolicy`. Approvers named by UPN or group name are resolved before comparison in every apply
section, so a re-run reports `Unchanged`; a `roleManagementPolicies` user approver must now be a
UPN or object id. Earlier versions could apply a group''s owner settings, a permanent-eligibility
opening included, to its member policy while the owner policy was not yet listed: review the
member policies of groups onboarded by an apply run. A refused policy read is
`PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the same run gets up to
30 seconds for its policies to appear, a `404 ResourceNotFound` counting as not there yet.
`Test-OERStructure` warns about unknown keys in `groups` and `pimPolicy`, and
`Invoke-OERStructure` no longer returns an eligibility request among its results.

`Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a
directory role''s PIM settings by role or policy id, Get also with `-All`. They return the Azure
cmdlets'' `RoleManagementPolicy` object with `Scope` `/` and need no Azure token. Unlike
`Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group
approvers and vice versa, and an empty list clears that side. An MFA and authentication-context
pair the call does not touch is left alone. The apply section `directoryRoleManagementPolicies[]`
runs between access reviews and the Azure sections and is not yet exported. `-Role` tab-completes
built-in role names, and a delegated sign-in needs Privileged Role Administrator to change a
policy. `Get-OERRequiredScope` lists the least-privilege permissions of the new cmdlets, and
`RoleManagement.ReadWrite.Directory` for `Set-OERGroup`.

'

            Prerelease               = 'preview0002'
        }
    }
}