Simon Vedder

Cloud Engineer · Zürich

Restore-RiskyRoleAssignment

Put back assignments from a backup file that Remove-RiskyRoleAssignment wrote.

Required permissionsOn Azure, Microsoft.Authorization/roleAssignments/write on the scope. On Entra, RoleManagement.ReadWrite.Directory (Connect-RiskyRolesAnalyzer -RequestWriteScopes).

Reads the JSON backup (or takes the same objects from the pipeline) and recreates each permanent assignment: Azure with New-AzRoleAssignment by principal, role definition id and scope; Entra by posting a new role assignment for the principal, role and directory scope. Restoring privilege is as serious as removing it, so every assignment is confirmed (ConfirmImpact High) and -WhatIf shows the plan.

Entries the module cannot restore are reported and skipped: PIM eligibility and activations (manage them in PIM), assignments inherited through a group (the group’s assignment was never removed), entries without the ids needed.

Syntax

Restore-RiskyRoleAssignment [-Path] <string> [-WhatIf] [-Confirm] [<CommonParameters>]

Restore-RiskyRoleAssignment -InputObject <Object[]> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

NameTypeRequiredPipelineDefaultDescription
-PathStringyesnoA backup file written by Remove-RiskyRoleAssignment.
-InputObjectObject[]yesyesBackup entries, for example from Get-Content backup.json | ConvertFrom-Json.

Supports -WhatIf and -Confirm.

Examples

Example 1

Restore-RiskyRoleAssignment -Path ./RiskyRolesAnalyzer-backup-20260906-142200.json -WhatIf

Example 2

Get-Content ./backup.json | ConvertFrom-Json | Where-Object PrincipalName -eq 'Deploy App' | Restore-RiskyRoleAssignment

Output

  • RiskyRolesAnalyzer.RiskyRoleAssignmentRestore

Generated from the comment-based help in the module. Same text as Get-Help Restore-RiskyRoleAssignment -Full, and as the copy on GitHub.