Omnicit.EntraRBAC.psd1
|
@{ RootModule = 'Omnicit.EntraRBAC.psm1' ModuleVersion = '1.1.0' CompatiblePSEditions = @('Core') GUID = '7b9e4a1c-2d6f-4f3a-9c8b-1e5d0a7c3f42' Author = 'Omnicit AB / Philip Haglund' CompanyName = 'Omnicit' Copyright = '(c) 2026 Omnicit AB' Description = 'Manage Entra ID and Azure RBAC building blocks across tenants: Entra ID groups, PIM, Administrative Units, Entitlement Management, Access Reviews, Azure resources and RBAC, plus a JSON inventory and declarative apply engine.' PowerShellVersion = '7.2' RequiredModules = @( @{ ModuleName = 'AzAuth'; ModuleVersion = '2.9.0' } @{ ModuleName = 'Microsoft.Graph.Authentication'; ModuleVersion = '2.36.0' } ) # Loaded via Update-TypeData in suffix.ps1 (Remove-Module does not clean type data). TypesToProcess = @() FormatsToProcess = @('Formats/Omnicit.EntraRBAC.Format.ps1xml') FunctionsToExport = @('Add-OERAccessPackageResourceRole','Add-OERAdministrativeUnitMember','Add-OERAdministrativeUnitScopedRole','Add-OERCatalogResource','Add-OERGroupEligibility','Add-OERGroupMember','Connect-OER','Disable-OEREligibleRoleAssignment','Disconnect-OER','Enable-OEREligibleRoleAssignment','Export-OERInventory','Get-OERAccessPackage','Get-OERAccessPackageAssignment','Get-OERAccessPackageAssignmentPolicy','Get-OERAccessPackageResourceRole','Get-OERAccessReviewDefinition','Get-OERAccessReviewInstance','Get-OERAccessReviewInstanceDecision','Get-OERActiveDirectoryRoleAssignment','Get-OERActiveRoleAssignment','Get-OERAdministrativeUnit','Get-OERAdministrativeUnitScopedRole','Get-OERAuthenticationContext','Get-OERCatalog','Get-OERCatalogResource','Get-OERConfiguration','Get-OERDirectoryRoleManagementPolicy','Get-OEREligibleDirectoryRoleAssignment','Get-OEREligibleRoleAssignment','Get-OERGroup','Get-OERGroupEligibility','Get-OERGroupMember','Get-OERGroupPimPolicy','Get-OERInventory','Get-OERManagementGroup','Get-OERRequiredScope','Get-OERResource','Get-OERResourceGroup','Get-OERRoleAssignment','Get-OERRoleDefinition','Get-OERRoleManagementPolicy','Get-OERSubscription','Invoke-OERAccessReviewInstanceDecision','Invoke-OERStructure','New-OERAccessPackage','New-OERAccessPackageApprovalStage','New-OERAccessPackageAssignment','New-OERAccessPackageAssignmentPolicy','New-OERAccessPackageRequestorScope','New-OERAccessPackageRequestorSettings','New-OERAccessReviewDefinition','New-OERAccessReviewStage','New-OERActiveDirectoryRoleAssignment','New-OERActiveRoleAssignment','New-OERAdministrativeUnit','New-OERCatalog','New-OERConfiguration','New-OEREligibleDirectoryRoleAssignment','New-OEREligibleRoleAssignment','New-OERGroup','New-OERPolicyNotificationRule','New-OERResourceGroup','New-OERRoleAssignment','Remove-OERAccessPackage','Remove-OERAccessPackageAssignment','Remove-OERAccessPackageAssignmentPolicy','Remove-OERAccessPackageResourceRole','Remove-OERAccessReviewDefinition','Remove-OERActiveDirectoryRoleAssignment','Remove-OERActiveRoleAssignment','Remove-OERAdministrativeUnit','Remove-OERAdministrativeUnitMember','Remove-OERAdministrativeUnitScopedRole','Remove-OERCatalog','Remove-OERCatalogResource','Remove-OERConfiguration','Remove-OEREligibleDirectoryRoleAssignment','Remove-OEREligibleRoleAssignment','Remove-OERGroup','Remove-OERGroupEligibility','Remove-OERGroupMember','Remove-OERResourceGroup','Remove-OERRoleAssignment','Send-OERAccessReviewReminder','Set-OERAccessPackage','Set-OERAccessPackageAssignmentPolicy','Set-OERAccessReviewDefinition','Set-OERAdministrativeUnit','Set-OERCatalog','Set-OERConfiguration','Set-OERDirectoryRoleManagementPolicy','Set-OERGroup','Set-OERGroupPimPolicy','Set-OERResourceGroup','Set-OERRoleAssignment','Set-OERRoleManagementPolicy','Stop-OERAccessReviewInstance','Test-OERStructure') CmdletsToExport = @() VariablesToExport = @() AliasesToExport = @() PrivateData = @{ PSData = @{ Tags = @('EntraID', 'Azure', 'RBAC', 'PIM', 'Identity', 'Governance', 'PSEdition_Core', 'Windows', 'Linux', 'MacOS') ProjectUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC' LicenseUri = 'https://github.com/Omnicit/Omnicit.EntraRBAC/blob/main/LICENSE' RequireLicenseAcceptance = $false ReleaseNotes = '## [1.1.0-preview0003] - 2026-09-30 `Invoke-OERStructure -Prune` no longer removes anything because a lookup failed. When a declared group member, owner or PIM eligibility, administrative unit member or scoped role, access package resource role, or role assignment under the same `scope` cannot be resolved, it is `Failed`, and the undeclared live entries of that collection are `Skipped`, rather than removed or `Extra`, with `prune withheld: declared entry ''<entry>'' could not be resolved`. Earlier versions could delete them, PIM eligibility and Azure role assignments included. A service principal in `roleAssignments` needs `"principalType": "ServicePrincipal"`. `Test-OERStructure` warns about an omitted `members`, `scopedRoles`, catalog `resources` or access package `resourceRoles` key, which still prunes, and `-Prune` lists them before writing; set such a key to `null` to leave it alone. PIM for Groups policies support approval. `Set-OERGroupPimPolicy` takes `-RequireApproval`, `-ApproverUser` and `-ApproverGroup`; `pimPolicy` takes `requireApproval` and `approvers { users[], groups[] }`, and `Get-OERInventory` exports them. Approvers named by UPN or group name are resolved before comparison in every apply section, so a re-run reports `Unchanged`; a `roleManagementPolicies` user approver must now be a UPN or object id. Earlier versions could apply a group''s owner settings, a permanent-eligibility opening included, to its member policy while the owner policy was not yet listed: review the member policies of groups onboarded by an apply run. A refused policy read is `PimPolicyReadFailed`, not `PimPolicyNotFound`, and a group created in the same run gets up to 30 seconds for its policies to appear. `Test-OERStructure` warns about unknown keys in `groups` and `pimPolicy`. `Get-OERDirectoryRoleManagementPolicy` and `Set-OERDirectoryRoleManagementPolicy` read and change a directory role''s PIM settings by role or policy id. They need no Azure token. Unlike `Set-OERRoleManagementPolicy`, approvers are replaced per side: `-ApproverUser` keeps the group approvers and vice versa, and an empty list clears that side. The apply section `directoryRoleManagementPolicies[]` runs before the Azure sections and is not yet exported. `Get-OERRequiredScope` lists the new cmdlets, and `RoleManagement.ReadWrite.Directory` for `Set-OERGroup`. Directory roles can be assigned: `New-`, `Get-` and `Remove-OEREligibleDirectoryRoleAssignment` and the same three for active assignments, and the apply section `directoryRoleAssignments[]`, after the directory-role policies. A permanent assignment the role''s policy does not allow is refused instead of opening the policy, and a group that is not role-assignable is refused before the request. `-Prune` touches only the role and assignment-type pairs the document declares, and never an activation, a member''s assignment inherited through a group, or a direct assignment of the signed-in identity or of a group it is a member of. Directory role names now match in any letter case. An ambiguous service principal display name is refused with the candidate ids instead of taking the first match, as `AmbiguousApplicationName` or `AmbiguousPrincipalName`; an ambiguous group principal name now also reports `AmbiguousPrincipalName`, not `PrincipalNotFound`. Graph refuses to change or remove a principal''s assignments of a role until its active assignment has run for five minutes; that row reports Failed with this cause. A removal Graph answers with `RoleAssignmentDoesNotExist` counts as done once a re-read finds the assignment gone. ' Prerelease = 'preview0003' } } } |