RiskMgmt
IdentityCommand.RiskMgmt is a PowerShell module that provides a set of easy-to-use commands, allowing you to interact with the Idira Risk Management API from within the PowerShell environment.
It builds on IdentityCommand for authentication - see Getting Started to install and connect, and the command reference for every command.
Risks and Findings
Get-RMRiskSummary gives the tenant-wide picture; Get-RMRiskType aggregates it by risk type, and Get-RMFinding lists the individual findings. Both list commands page automatically:
# The whole tenant, by entity type and category
Get-RMRiskSummary
# Critical and high risk types, most recently updated first
Get-RMRiskType -severity CRITICAL, HIGH -sort updatedAt:desc
# Open findings against users, updated in the last week
Get-RMFinding -status OPEN -entityTypes USER -daysSinceLastUpdate 7
A finding can be snoozed for a period, which excludes it from risk summary counts until the snooze expires:
Suspend-RMFinding -findingId $id -durationDays 30 -reason 'Accepted risk pending Q3 review'
# Findings pipe straight in
Get-RMFinding -riskTypeId $riskTypeId | Suspend-RMFinding -durationDays 7 -reason 'Waiting for the vendor patch'
# And back out again
Get-RMFinding -status SNOOZED | Resume-RMFinding
Recommendations and Remediations
# Blueprint recommendations, and the tagged account counts under one of them
Get-RMRecommendation
Get-RMRecommendationTagCount -recommendationType SECURE_STANDING_ACCESS_UNIX_602 -entityTags production
# System and custom remediations
Get-RMRemediation -entityTypes USER
New-RMRemediation -entityType USER -name 'Rotate Privileged Account Password' -remediationText 'Rotate the password using Idira Password Manager.'
Risk Posture
Get-RMRiskPostureDiscovery
Get-RMRiskPostureProgress