├── .devcontainer ├── Dockerfile └── devcontainer.json ├── Classification ├── Classification_AppRoles.json ├── Classification_DeviceManagementRoles.json └── Classification_EntraIdDirectoryRoles.json ├── EAS_EAM_AzureRBAC_TabularSummary.pdf ├── EntraOps_Classification ├── Classification_AadResources.Param.json ├── Classification_AadResources.json ├── Classification_AppRoles.json ├── Classification_Defender.json └── Classification_DeviceManagement.json ├── LICENSE ├── LifecycleWorkflows └── CustomExtensions │ ├── Create-AADPrivilegedAccount.json │ ├── Disable-AADPrivilegedAccount.json │ └── Generate-AADPrivilegedAccountTAP.json ├── PrivilegedOperations ├── ArmApiRequest.csv └── GraphApiRequest.csv ├── README.md └── Scripts ├── Export-EntraOpsClassificationAppRoles.ps1 ├── Export-EntraOpsClassificationDeviceManagementRoles.ps1 ├── Export-EntraOpsClassificationDirectoryRoles.ps1 ├── Get-AadHighPrivilegedRolesAndAssignments.ps1 ├── Get-AadObjectsFromAzureRBAC.ps1 └── Get-AzEARoleMembers.ps1 /.devcontainer/Dockerfile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/.devcontainer/Dockerfile -------------------------------------------------------------------------------- /.devcontainer/devcontainer.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/.devcontainer/devcontainer.json -------------------------------------------------------------------------------- /Classification/Classification_AppRoles.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Classification/Classification_AppRoles.json -------------------------------------------------------------------------------- /Classification/Classification_DeviceManagementRoles.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Classification/Classification_DeviceManagementRoles.json -------------------------------------------------------------------------------- /Classification/Classification_EntraIdDirectoryRoles.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Classification/Classification_EntraIdDirectoryRoles.json -------------------------------------------------------------------------------- /EAS_EAM_AzureRBAC_TabularSummary.pdf: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EAS_EAM_AzureRBAC_TabularSummary.pdf -------------------------------------------------------------------------------- /EntraOps_Classification/Classification_AadResources.Param.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EntraOps_Classification/Classification_AadResources.Param.json -------------------------------------------------------------------------------- /EntraOps_Classification/Classification_AadResources.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EntraOps_Classification/Classification_AadResources.json -------------------------------------------------------------------------------- /EntraOps_Classification/Classification_AppRoles.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EntraOps_Classification/Classification_AppRoles.json -------------------------------------------------------------------------------- /EntraOps_Classification/Classification_Defender.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EntraOps_Classification/Classification_Defender.json -------------------------------------------------------------------------------- /EntraOps_Classification/Classification_DeviceManagement.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/EntraOps_Classification/Classification_DeviceManagement.json -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/LICENSE -------------------------------------------------------------------------------- /LifecycleWorkflows/CustomExtensions/Create-AADPrivilegedAccount.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/LifecycleWorkflows/CustomExtensions/Create-AADPrivilegedAccount.json -------------------------------------------------------------------------------- /LifecycleWorkflows/CustomExtensions/Disable-AADPrivilegedAccount.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/LifecycleWorkflows/CustomExtensions/Disable-AADPrivilegedAccount.json -------------------------------------------------------------------------------- /LifecycleWorkflows/CustomExtensions/Generate-AADPrivilegedAccountTAP.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/LifecycleWorkflows/CustomExtensions/Generate-AADPrivilegedAccountTAP.json -------------------------------------------------------------------------------- /PrivilegedOperations/ArmApiRequest.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/PrivilegedOperations/ArmApiRequest.csv -------------------------------------------------------------------------------- /PrivilegedOperations/GraphApiRequest.csv: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/PrivilegedOperations/GraphApiRequest.csv -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/README.md -------------------------------------------------------------------------------- /Scripts/Export-EntraOpsClassificationAppRoles.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Export-EntraOpsClassificationAppRoles.ps1 -------------------------------------------------------------------------------- /Scripts/Export-EntraOpsClassificationDeviceManagementRoles.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Export-EntraOpsClassificationDeviceManagementRoles.ps1 -------------------------------------------------------------------------------- /Scripts/Export-EntraOpsClassificationDirectoryRoles.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Export-EntraOpsClassificationDirectoryRoles.ps1 -------------------------------------------------------------------------------- /Scripts/Get-AadHighPrivilegedRolesAndAssignments.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Get-AadHighPrivilegedRolesAndAssignments.ps1 -------------------------------------------------------------------------------- /Scripts/Get-AadObjectsFromAzureRBAC.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Get-AadObjectsFromAzureRBAC.ps1 -------------------------------------------------------------------------------- /Scripts/Get-AzEARoleMembers.ps1: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/Cloud-Architekt/AzurePrivilegedIAM/HEAD/Scripts/Get-AzEARoleMembers.ps1 --------------------------------------------------------------------------------