IdentityCommand is a PowerShell module that wraps the REST API for a Palo Alto Idira (formerly CyberArk) Identity tenant, giving you easy-to-use commands for authentication (including MFA/SAML/OIDC flows) and administration - users, roles, applications, organizations, authentication policies, SCIM provisioning, and more - all from within PowerShell.
The module has been in development for a few years, initially focused on authentication. Coverage is expanding significantly to reach near-complete coverage of the Identity Administration API, and IdentityCommand is also the foundation for a growing family of other pspete modules that administer the wider Idira SaaS platform - e.g. IdentityCommand.DPA, which builds on IdentityCommand's authentication to administer Idira DPA.
- Prior to a Version 1.0.0 release:
- Expect changes
- Things may break
- Issues / PRs are encouraged & appreciated
- Many commands are built from documented API shapes but not yet exercised against a live tenant - see Help Us Test below, your feedback genuinely shapes what ships next.
- Most of the Identity Administration API is now covered, but real-world usage is still expected to shape further changes to command names, parameters/parameter names, and how commands are grouped - some may split into companion commands, others may combine. These patterns only emerge once commands are actually used, so don't consider anything final yet.
- To develop & publish consistently coded PowerShell functions for available Idira (CyberArk) Identity APIs.
The current main use cases of the project are focused on authentication to the Idira (CyberArk) Identity platform.
An example command to initiate authentication to a specified tenant is shown here:
PS C:\> $Credential = Get-Credential
PS C:\> New-IDSession -tenant_url https://sometenant.id.cyberark.cloud -Credential $CredentialThis allows initial authentication to progress as well as selection and answer of any required MFA challenges.
Once successfully authenticated, all IdentityCommand module commands which require an authenticated session can be used from within the same PowerShell session.
Service User credentials can be used to request an authentication token for the Identity Platform:
PS C:\> $Credential = Get-Credential
PS C:\> New-IDPlatformToken -tenant_url https://sometenant.id.cyberark.cloud -Credential $CredentialThis allows initial authentication using a separate dedicated Service user for API activities.
Consult the vendor documentation for guidance on setting up a dedicated API Service user for non-interactive API use.
Once successfully authenticated, all IdentityCommand module commands which require an authenticated session can be used from within the same PowerShell session.
IdentityCommand authentication functions contain methods which can be used to obtain authenticated session data & authentication tokens:
You may have a scenario where you want to use APIs for which we have not yet developed, built or published module commands.
The GetToken method of the object returned on successful authentication can be invoked to obtain a bearer token to be used for further requests.
PS C:\> $Session = New-IDPlatformToken -tenant_url https://sometenant.id.cyberark.cloud -Credential $Credential
PS C:\> $Session.GetToken()
Name Value
---- -----
Authorization Bearer eyPhbSciPiJEUzT1NEIsInR5cCI6IkpXYZ...The GetWebSession method can be used in a similar way to GetToken, except this method returns the websession object for the authenticated session instead of a Bearer token.
PS C:\> $Session = New-IDSession -tenant_url https://sometenant.id.cyberark.cloud -Credential $Credential
PS C:\> $session.GetWebSession()
Headers : {[accept, */*], [X-IDAP-NATIVE-CLIENT, True]}
Cookies : System.Net.CookieContainer
UseDefaultCredentials : False
Credentials :
Certificates :
UserAgent : Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.22621.1778
Proxy :
MaximumRedirection : -1The Websession can be used for any further requests you require.
PS C:\> $Websession = $session.GetWebSession()
PS C:\> Invoke-RestMethod -WebSession $websession `
-Method Post `
-Uri https://somedomain .id.cyberark.cloud `
-Body @{SomeProperty = 'SomeValue'} | ConvertTo-JsonThe Get-IDSession command can be used to return data from the module scope:
PS C:\> Get-IDSession
Name Value
---- -----
tenant_url https://abc1234.id.cyberark.cloud
User some.user@somedomain.com
TenantId ABC1234
SessionId 1337CbGbPunk3Sm1ff5ess510nD3tai75
WebSession Microsoft.PowerShell.Commands.WebRequestSession
StartTime 12/02/2024 22:58:13
ElapsedTime 00:25:30
LastCommand System.Management.Automation.InvocationInfo
LastCommandTime 12/02/2024 23:23:07
LastCommandResults {"success":true,"Result":{"SomeResult"}}Executing this command exports variables like the URL, Username & WebSession object for the authenticated session from IdentityCommand into your local scope, either for use in other requests outside of the module scope, or for informational purposes.
Return data also includes details such as session start time, elapsed time, last command time, as well as data for the last invoked command and the results of the previous command.
IdentityCommand currently ships 170+ commands, grouped into the areas below. The full list moves fast enough that it's not reproduced command-by-command here - instead, once the module is imported:
# List every command in the module, grouped by area
Get-Command -Module IdentityCommand | Group-Object { $_.Name.Split('-')[1] -replace '^ID' }
# Get detailed help, including examples, for any command
Get-Help Get-IDUser -FullEvery command also has a corresponding reference page under docs/collections/_commands, which is the same content Get-Help displays.
| Area | Covers |
|---|---|
| Session / Authentication | Interactive & service-account sign-in (credential, SAML, MFA challenges), session lifecycle, platform tokens |
| Users | User CRUD, roles, attributes, security questions, U2F devices, sessions, invites, identity verification, password/lock management |
| Roles | Roles, membership (users/roles/groups), administrative permissions, dynamic role scripts |
| Applications | Application catalog CRUD, permissions, tags, icons, personal apps & secured items, CSV import |
| Organizations | Organization/tenant-partition administration, membership, administrators, permissions |
| Policies | Authentication profiles & policies, MFA assurance levels, OTP/password complexity settings |
| SCIM | SCIM-based provisioning for users, groups, containers, container permissions & privileged data |
| Tenant | Tenant configuration, cnames, suffixes, security questions, message templates |
| Workflow | Access-request workflow jobs and approval/denial events |
| Devices | Device registration & management |
| Core | Lower-level helpers - ad-hoc SQL queries, permission lookups, download URLs, password generation |
Prior to a 1.0.0 release, some commands are built from documented or captured API shapes but haven't yet been exercised against a live tenant, or only partially confirmed. If you're able to try one of these against your own tenant, open an issue with what you found (works as-is, needs a fix, or the request shape is wrong) - it's genuinely the fastest way to move a command from "should work" to "confirmed".
The current list is:
| Command | What's unconfirmed |
|---|---|
Get-/New-/Set-/Remove-IDSCIMContainer |
Built from the vendor's OpenAPI schema, but never exercised live - this tenant doesn't provision the SCIM Container resource type (check with Get-IDSCIMResourceType) |
Get-/New-/Set-/Remove-IDSCIMContainerPermission |
Same - needs a tenant that provisions SCIM ContainerPermission |
Get-/New-/Set-/Remove-IDSCIMPrivilegedData |
Same - needs a tenant that provisions SCIM PrivilegedData |
- Requires Powershell Core (recommended), or Windows PowerShell (version 5.1)
- an Idira (CyberArk) Identity tenant
- An Account to Access Idira (CyberArk) Identity
Users can install IdentityCommand from GitHub or the PowerShell Gallery.
Choose any of the following ways to download the module and install it:
This is the easiest and most popular way to install the module:
-
Open a PowerShell prompt
-
Run the following command:
Install-Module -Name IdentityCommand -Scope CurrentUserThe module files can be manually copied to one of your PowerShell module directories.
Use the following command to get the paths to your local PowerShell module folders:
$env:PSModulePath.split(';')
The module files must be placed in one of the listed directories, in a folder called IdentityCommand.
More: about_PSModulePath
The module files are available to download using a variety of methods:
- Download from the module from the PowerShell Gallery:
- Run the PowerShell command
Save-Module -Name IdentityCommand -Path C:\temp - Copy the
C:\temp\IdentityCommandfolder to your "Powershell Modules" directory of choice.
- Run the PowerShell command
- Download the latest GitHub release
- Unblock & Extract the archive
- Rename the extracted
IdentityCommand-v#.#.#folder toIdentityCommand - Copy the
IdentityCommandfolder to your "Powershell Modules" directory of choice.
- Download the
mainbranch- Unblock & Extract the archive
- Copy the
IdentityCommand(\<Archive Root>\IdentityCommand-master\IdentityCommand) folder to your "Powershell Modules" directory of choice.
Validate Install:
Get-Module -ListAvailable IdentityCommand
Import the module:
Import-Module IdentityCommand
List Module Commands:
Get-Command -Module IdentityCommand
Get detailed information on specific commands:
Get-Help New-IDSession -Full
Please support continued development; consider sponsoring @pspete on GitHub Sponsors
All notable changes to this project will be documented in the Changelog
- Pete Maan - pspete
This project is licensed under the MIT License.
Any and all contributions to this project are appreciated.
See the CONTRIBUTING.md for a few more details.
IdentityCommand is neither developed nor supported by Palo Alto / CyberArk; any official support channels offered by the vendor are not appropriate for seeking help with the IdentityCommand module.
Help and support should be sought by opening an issue.
Priority support could be considered for sponsors of @pspete, contact us to discuss options.
