Skip to content

Instantly share code, notes, and snippets.

Created March 20, 2023 10:13
Show Gist options
  • Save davidobrien1985/8b510deb60f39c18f7183caf5c4b9ac8 to your computer and use it in GitHub Desktop.
Save davidobrien1985/8b510deb60f39c18f7183caf5c4b9ac8 to your computer and use it in GitHub Desktop.
param (
[bool]$DeleteRoleAssignments = $false
if (-not (Get-Module -ListAvailable -Name Az)) {
Write-Output "Installing Az module..."
Install-Module -Name Az -Scope CurrentUser -Repository PSGallery -Force
$subIds = Get-AzSubscription | Select-Object -ExpandProperty SubscriptionId
foreach ($subId in $subIds) {
Set-AzContext -SubscriptionId $subId
$resourceGroups = Get-AzResourceGroup
foreach ($resourceGroup in $resourceGroups) {
try {
$assignments = Get-AzRoleAssignment -ResourceGroupName $resourceGroup.ResourceGroupName -ErrorAction SilentlyContinue
foreach ($assignment in $assignments) {
if ($assignment.Properties.ObjectType -eq "Unknown") {
Write-Output "Found role assignment $($assignment.RoleDefinitionName) for $($assignment.DisplayName) in $($resourceGroup.ResourceGroupName) in $($subId)"
if ($DeleteRoleAssignments) {
Write-Output "Removing role assignment $($assignment.RoleDefinitionName) for $($assignment.DisplayName) in $($resourceGroup.ResourceGroupName) in $($subId)"
Remove-AzRoleAssignment -ObjectId $assignment.ObjectId -Scope $assignment.Scope -RoleDefinitionName $assignment.RoleDefinitionName -Force
catch {
Write-Error "Error processing resource group $($resourceGroup.ResourceGroupName): $_"
try {
$subscriptionsAssignments = Get-AzRoleAssignment -Scope "/subscriptions/$subId" -ErrorAction SilentlyContinue
foreach ($assignment in $subscriptionsAssignments) {
if ($assignment.Properties.ObjectType -eq "Unknown") {
Write-Output "Found role assignment $($assignment.RoleDefinitionName) for $($assignment.DisplayName) in subscription $($subId)"
if ($DeleteRoleAssignments) {
Write-Output "Removing role assignment $($assignment.RoleDefinitionName) for $($assignment.DisplayName) in subscription $($subId)"
Remove-AzRoleAssignment -ObjectId $assignment.ObjectId -Scope $assignment.Scope -RoleDefinitionName $assignment.RoleDefinitionName -Force
catch {
Write-Error "Error processing subscription-level assignments for subscription $($subId): $_"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment