Omnicit.EntraRBAC
1.1.0-preview0003
Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.
Minimum PowerShell version
7.2
See the version list below for details.
Installation Options
Owners
Copyright
(c) 2026 Omnicit AB
Package Details
Author(s)
- Omnicit AB / Philip Haglund
Tags
EntraID Azure RBAC PIM Identity Governance Windows Linux MacOS
Functions
Add-OERAccessPackageResourceRole Add-OERAdministrativeUnitMember Add-OERAdministrativeUnitScopedRole Add-OERCatalogResource Add-OERGroupEligibility Add-OERGroupMember Connect-OER Disable-OEREligibleRoleAssignment Disconnect-OER Enable-OEREligibleRoleAssignment Export-OERInventory Get-OERAccessPackage Get-OERAccessPackageAssignment Get-OERAccessPackageAssignmentPolicy Get-OERAccessPackageResourceRole Get-OERAccessReviewDefinition Get-OERAccessReviewInstance Get-OERAccessReviewInstanceDecision Get-OERActiveDirectoryRoleAssignment Get-OERActiveRoleAssignment Get-OERAdministrativeUnit Get-OERAdministrativeUnitScopedRole Get-OERAuthenticationContext Get-OERCatalog Get-OERCatalogResource Get-OERConfiguration Get-OERDirectoryRoleManagementPolicy Get-OEREligibleDirectoryRoleAssignment Get-OEREligibleRoleAssignment Get-OERGroup Get-OERGroupEligibility Get-OERGroupMember Get-OERGroupPimPolicy Get-OERInventory Get-OERManagementGroup Get-OERRequiredScope Get-OERResource Get-OERResourceGroup Get-OERRoleAssignment Get-OERRoleDefinition Get-OERRoleManagementPolicy Get-OERSubscription Invoke-OERAccessReviewInstanceDecision Invoke-OERStructure New-OERAccessPackage New-OERAccessPackageApprovalStage New-OERAccessPackageAssignment New-OERAccessPackageAssignmentPolicy New-OERAccessPackageRequestorScope New-OERAccessPackageRequestorSettings New-OERAccessReviewDefinition New-OERAccessReviewStage New-OERActiveDirectoryRoleAssignment New-OERActiveRoleAssignment New-OERAdministrativeUnit New-OERCatalog New-OERConfiguration New-OEREligibleDirectoryRoleAssignment New-OEREligibleRoleAssignment New-OERGroup New-OERPolicyNotificationRule New-OERResourceGroup New-OERRoleAssignment Remove-OERAccessPackage Remove-OERAccessPackageAssignment Remove-OERAccessPackageAssignmentPolicy Remove-OERAccessPackageResourceRole Remove-OERAccessReviewDefinition Remove-OERActiveDirectoryRoleAssignment Remove-OERActiveRoleAssignment Remove-OERAdministrativeUnit Remove-OERAdministrativeUnitMember Remove-OERAdministrativeUnitScopedRole Remove-OERCatalog Remove-OERCatalogResource Remove-OERConfiguration Remove-OEREligibleDirectoryRoleAssignment Remove-OEREligibleRoleAssignment Remove-OERGroup Remove-OERGroupEligibility Remove-OERGroupMember Remove-OERResourceGroup Remove-OERRoleAssignment Send-OERAccessReviewReminder Set-OERAccessPackage Set-OERAccessPackageAssignmentPolicy Set-OERAccessReviewDefinition Set-OERAdministrativeUnit Set-OERCatalog Set-OERConfiguration Set-OERDirectoryRoleManagementPolicy Set-OERGroup Set-OERGroupPimPolicy Set-OERResourceGroup Set-OERRoleAssignment Set-OERRoleManagementPolicy Stop-OERAccessReviewInstance Test-OERStructure
PSEditions
Dependencies
-
- AzAuth (>= 2.9.0)
- Microsoft.Graph.Authentication (>= 2.36.0)
Release Notes
## [1.1.0-preview0003] - 2026-09-30
`Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared
group member, owner or PIM eligibility, administrative unit member or scoped role, access package
resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and the
undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`, with
`prune withheld: declared entry '<entry>' could not be resolved`. Earlier versions could delete
them, PIM eligibility and Azure role assignments included. A service principal in `roleAssignments`
needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an omitted `members`,
`scopedRoles`, catalog `resources` or access package `resourceRoles` key, which still prunes, and
`-Prune` lists them before writing; set such a key to `null` to leave it alone.
PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`,
`-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and `approvers { users[],
groups[] }`, and `Get-OERInventory` exports them. Approvers named by UPN or group name are resolved
before comparison in every apply section, so a re-run reports `Unchanged`; a
`roleManagementPolicies` user approver must now be a UPN or object id. Earlier versions could apply
a group's owner settings, a permanent-eligibility opening included, to its member policy while the
owner policy was not yet listed: review the member policies of groups onboarded by an apply run. A
refused policy read is `PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the
same run gets up to 30 seconds for its policies to appear. `Test-OERStructure` warns about unknown
keys in `groups` and `pimPolicy`.
`Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a
directory role's PIM settings by role or policy id. They need no Azure token. Unlike
`Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group
approvers and vice versa, and an empty list clears that side. The apply section
`directoryRoleManagementPolicies[]` runs before the Azure sections and is not yet exported.
`Get-OERRequiredScope` lists the new cmdlets, and `RoleManagement.ReadWrite.Directory` for
`Set-OERGroup`.
Directory roles can be assigned: `New-`, `Get-` and `Remove-OEREligibleDirectoryRoleAssignment` and
the same three for active assignments, and the apply section `directoryRoleAssignments[]`, after the
directory-role policies. A permanent assignment the role's policy does not allow is refused instead
of opening the policy, and a group that is not role-assignable is refused before the request.
`-Prune` touches only the role and assignment-type pairs the document declares, and never an
activation, a member's assignment inherited through a group, or a direct assignment of the signed-in
identity or of a group it is a member of. Directory role names now match in any letter case. An
ambiguous service principal display name is refused with the candidate ids instead of taking the
first match, as `AmbiguousApplicationName` or `AmbiguousPrincipalName`; an ambiguous group principal
name now also reports `AmbiguousPrincipalName`, not `PrincipalNotFound`. Graph refuses to change or
remove a principal's assignments of a role until its active assignment has run for five minutes;
that row reports Failed with this cause. A removal Graph answers with `RoleAssignmentDoesNotExist`
counts as done once a re-read finds the assignment gone.
FileList
- Omnicit.EntraRBAC.nuspec
- Omnicit.EntraRBAC.psd1
- Formats\Omnicit.EntraRBAC.Format.ps1xml
- en-US\about_Omnicit.EntraRBAC.help.txt
- Omnicit.EntraRBAC.psm1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 3 | 10/2/2026 |
| 1.1.1-previe... | 5 | 10/1/2026 |
| 1.1.0 | 22 | 10/1/2026 |
| 1.1.0-previe... | 21 | 10/1/2026 |
| 1.1.0-previe... (current version) | 4 | 9/30/2026 |
| 1.1.0-previe... | 3 | 9/29/2026 |
| 1.1.0-previe... | 4 | 9/28/2026 |
| 1.0.2-previe... | 4 | 9/24/2026 |
| 1.0.2-previe... | 4 | 9/23/2026 |
| 1.0.1 | 10 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 4 | 9/23/2026 |
| 1.0.1-previe... | 5 | 9/23/2026 |
| 1.0.0 | 8 | 9/18/2026 |