IdentityCommand.RiskMgmt

IdentityCommand.RiskMgmt is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Risk Management API from within the PowerShell environment.

It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.

Risks and Findings

Get-RMRiskSummary gives the tenant-wide picture; Get-RMRiskType aggregates it by risk type, and Get-RMFinding lists the individual findings. Both list commands page automatically:

# The whole tenant, by entity type and category
Get-RMRiskSummary

# Critical and high risk types, most recently updated first
Get-RMRiskType -severity CRITICAL, HIGH -sort updatedAt:desc

# Open findings against users, updated in the last week
Get-RMFinding -status OPEN -entityTypes USER -daysSinceLastUpdate 7

A finding can be snoozed for a period, which excludes it from risk summary counts until the snooze expires:

Suspend-RMFinding -findingId $id -durationDays 30 -reason 'Accepted risk pending Q3 review'

# Findings pipe straight in
Get-RMFinding -riskTypeId $riskTypeId | Suspend-RMFinding -durationDays 7 -reason 'Waiting for the vendor patch'

# And back out again
Get-RMFinding -status SNOOZED | Resume-RMFinding

Recommendations and Remediations

# Blueprint recommendations, and the tagged account counts under one of them
Get-RMRecommendation
Get-RMRecommendationTagCount -recommendationType SECURE_STANDING_ACCESS_UNIX_602 -entityTags production

# System and custom remediations
Get-RMRemediation -entityTypes USER

New-RMRemediation -entityType USER -name 'Rotate Privileged Account Password' -remediationText 'Rotate the password using Idira Password Manager.'

Risk Posture

Get-RMRiskPostureDiscovery
Get-RMRiskPostureProgress