Test-MtEntraAgentDirectoryRoles
SYNOPSIS
Finds Agent Identities and Blueprint Principals assigned privileged Entra directory roles.
SYNTAX
Test-MtEntraAgentDirectoryRoles [-ProgressAction <ActionPreference>] [<CommonParameters>]
DESCRIPTION
Checks whether any Agent Identity or Agent Identity Blueprint Principal has been assigned privileged Entra directory roles (e.g., Global Administrator, Privileged Role Administrator, Agent ID Administrator, Application Administrator). Workload identities and AI agents should use least-privilege scoped permissions rather than broad administrative directory roles.
EXAMPLES
EXAMPLE 1
Test-MtEntraAgentDirectoryRoles
PARAMETERS
-ProgressAction
Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.
Type: ActionPreference
Parameter Sets: (All)
Aliases: proga
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
CommonParameters
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
INPUTS
OUTPUTS
System.Boolean
NOTES
RELATED LINKS
https://maester.dev/docs/commands/Test-MtEntraAgentDirectoryRoles
https://learn.microsoft.com/graph/api/rbacapplication-list-roleassignments?view=graph-rest-1.0