Skript Beschreibung
Zusammenfassung: PIM-Review-Automator - Audits Privileged Identity Management (PIM) role assignments.
Prüfstatus: Ungeprüft
Aus dem bestehenden GitHub-Bestand übernommen; fachliche und Tenant-Abnahme ausstehend.
Identifies users with permanent administrative assignments and compares them
against eligible assignments to ensure the Principle of Least Privilege (PoLP).
#>
[CmdletBinding()]
param ()
process {
Write-Host "[INFO] Auditing PIM Role Assignments..." -ForegroundColor Cyan
try {
# Fetch all role assignments
$Assignments = Get-MgRoleManagementDirectoryRoleAssignment -All
$PermanentAdmins = $Assignments | Where-Object { $_