Omnicit.EntraRBAC

1.1.0-preview0003

Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.

Minimum PowerShell version

7.2

This is a prerelease version of Omnicit.EntraRBAC.
There is a newer prerelease version of this module available.
See the version list below for details.

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name Omnicit.EntraRBAC -RequiredVersion 1.1.0-preview0003 -AllowPrerelease

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name Omnicit.EntraRBAC -Version 1.1.0-preview0003 -Prerelease

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Omnicit AB

Package Details

Author(s)

  • Omnicit AB / Philip Haglund

Tags

EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS

Functions

Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure

PSEditions

Core

Dependencies

Release Notes

## [1.1.0-preview0003] - 2026-09-30

`Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared
group member, owner or PIM eligibility, administrative unit member or scoped role, access package
resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and the
undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`, with
`prune withheld: declared entry '<entry>' could not be resolved`. Earlier versions could delete
them, PIM eligibility and Azure role assignments included. A service principal in `roleAssignments`
needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an omitted `members`,
`scopedRoles`, catalog `resources` or access package `resourceRoles` key, which still prunes, and
`-Prune` lists them before writing; set such a key to `null` to leave it alone.

PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`,
`-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and `approvers { users[],
groups[] }`, and `Get-OERInventory` exports them. Approvers named by UPN or group name are resolved
before comparison in every apply section, so a re-run reports `Unchanged`; a
`roleManagementPolicies` user approver must now be a UPN or object id. Earlier versions could apply
a group's owner settings, a permanent-eligibility opening included, to its member policy while the
owner policy was not yet listed: review the member policies of groups onboarded by an apply run. A
refused policy read is `PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the
same run gets up to 30 seconds for its policies to appear. `Test-OERStructure` warns about unknown
keys in `groups` and `pimPolicy`.

`Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a
directory role's PIM settings by role or policy id. They need no Azure token. Unlike
`Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group
approvers and vice versa, and an empty list clears that side. The apply section
`directoryRoleManagementPolicies[]` runs before the Azure sections and is not yet exported.
`Get-OERRequiredScope` lists the new cmdlets, and `RoleManagement.ReadWrite.Directory` for
`Set-OERGroup`.

Directory roles can be assigned: `New-`, `Get-` and `Remove-OEREligibleDirectoryRoleAssignment` and
the same three for active assignments, and the apply section `directoryRoleAssignments[]`, after the
directory-role policies. A permanent assignment the role's policy does not allow is refused instead
of opening the policy, and a group that is not role-assignable is refused before the request.
`-Prune` touches only the role and assignment-type pairs the document declares, and never an
activation, a member's assignment inherited through a group, or a direct assignment of the signed-in
identity or of a group it is a member of. Directory role names now match in any letter case. An
ambiguous service principal display name is refused with the candidate ids instead of taking the
first match, as `AmbiguousApplicationName` or `AmbiguousPrincipalName`; an ambiguous group principal
name now also reports `AmbiguousPrincipalName`, not `PrincipalNotFound`. Graph refuses to change or
remove a principal's assignments of a role until its active assignment has run for five minutes;
that row reports Failed with this cause. A removal Graph answers with `RoleAssignmentDoesNotExist`
counts as done once a re-read finds the assignment gone.

FileList

Version History

Version Downloads Last updated
1.1.1-previe... 3 10/2/2026
1.1.1-previe... 3 10/2/2026
1.1.1-previe... 5 10/1/2026
1.1.0 22 10/1/2026
1.1.0-previe... 21 10/1/2026
1.1.0-previe... (current version) 4 9/30/2026
1.1.0-previe... 3 9/29/2026
1.1.0-previe... 4 9/28/2026
1.0.2-previe... 4 9/24/2026
1.0.2-previe... 4 9/23/2026
1.0.1 10 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 4 9/23/2026
1.0.1-previe... 5 9/23/2026
1.0.0 8 9/18/2026
Show less