Skip to main content
Version: 2.2.1-preview

Test-MtEntraAgentDirectoryRoles

SYNOPSIS

Finds Agent Identities and Blueprint Principals assigned privileged Entra directory roles.

SYNTAX

Test-MtEntraAgentDirectoryRoles [-ProgressAction <ActionPreference>] [<CommonParameters>]

DESCRIPTION

Checks whether any Agent Identity or Agent Identity Blueprint Principal has been assigned privileged Entra directory roles (e.g., Global Administrator, Privileged Role Administrator, Agent ID Administrator, Application Administrator). Workload identities and AI agents should use least-privilege scoped permissions rather than broad administrative directory roles.

EXAMPLES

EXAMPLE 1

Test-MtEntraAgentDirectoryRoles

PARAMETERS

-ProgressAction

Determines how PowerShell responds to progress updates generated by a script, cmdlet, or provider, such as the progress bars generated by Write-Progress.

Type: ActionPreference
Parameter Sets: (All)
Aliases: proga

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

OUTPUTS

System.Boolean

NOTES

https://maester.dev/docs/commands/Test-MtEntraAgentDirectoryRoles

https://learn.microsoft.com/graph/api/rbacapplication-list-roleassignments?view=graph-rest-1.0