IdentityCommand.AccessRequest is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Access Request API from within the PowerShell environment.
It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.
Access Requests
Get-ARRequest returns the requests you can see - those you raised, and those assigned to you as an approver. Narrow by role, or by any of the filter criteria:
# Everything visible to you
Get-ARRequest
# Just the ones waiting on your approval
Get-ARRequest -requestState PENDING -requestRole APPROVER
# Raised by a given user in the last week
Get-ARRequest -createdBy 'John.Doe@cyberark.com' -createdAfter (Get-Date).AddDays(-7)
# A single request
Get-ARRequest -requestId 8a45155d-0273-4bc8-8d45-9fe3f4d4de6d
Those criteria are assembled into the filter expression the service expects. For anything they do not express, -filter takes an expression directly - note the service requires every expression to be complete within parentheses:
Get-ARRequest -filter "((requestState eq finished) and (priority gt 5))"
Raising a Request
The questions a request must answer vary by target category and request type, and the service describes them rather than the module fixing them. Ask for the form first, then build -requestDetails from the keys it returns:
$Form = Get-ARRequestForm -targetCategory CLOUD_CONSOLE -requestType ON_DEMAND
$Form.requestForm.questions | Where-Object required -eq $true | Select-Object key, title, valueType
New-ARRequest -targetCategory CLOUD_CONSOLE -requestType ON_DEMAND -requestDetails @{
locationType = 'Azure'
roleId = '/providers/Microsoft.Authorization/roleDefinitions/3ae3fb29-0000-4ccd-bf80-542e7b26e081'
workspaceId = 'subscriptions/15380d28-0024-4c6c-8a19-fb1dcf4d9a0d'
orgId = '30ddc194-66d2-4bc9-adc2-154977bb0419'
reason = 'I need access to change the subscription settings.'
priority = 'Low'
requestDate = '2026-09-30'
timezone = 'Europe/London'
timeFrom = '09:00'
timeTo = '17:00'
}
A request you raised can be cancelled while it is still open - before an approver has handled it, or before the approved access window starts:
Get-ARRequest -requestState PENDING -requestRole CREATOR | Stop-ARRequest -cancelReason 'Raised in error'
Approving and Rejecting
Requests assigned to you as an approver are handled with Approve-ARRequest and Deny-ARRequest. Once one assigned approver has handled a request, no other can:
Approve-ARRequest -requestId $id -finalizationReason 'All requirements met'
Get-ARRequest -requestState PENDING -requestRole APPROVER | Deny-ARRequest -finalizationReason 'Raise a change record first'