functions/roleManagement/roleDefinitions/Invoke-AzurePIMroleDefinition.ps1

function Invoke-AzurePIMroleDefinition {
    [CmdletBinding()]
    Param (
        [string[]] $SpecificResources,
        [System.Management.Automation.PSCmdlet]
        $Cmdlet = $PSCmdlet
    )
    
    begin
    {
        $resourceName = "roleDefinitions"
        if (!$script:desiredConfiguration[$resourceName]) {
            Stop-PSFFunction -String "AzurePIM.NoDefinitions" -StringValues "roleDefinitions"
            return
        }
        Test-AzureConnection
        $secureStringToken = (Get-AzAccessToken -AsSecureString -ResourceUrl $script:apiBaseUrl).Token
        $azureToken = [System.Net.NetworkCredential]::new('', $secureStringToken).Password
    }

    process {
        if (Test-PSFFunctionInterrupt) { return }
        $testResults = Test-AzurePIMroleDefinition -Cmdlet $Cmdlet

        foreach ($result in $testResults) {
            Beautify-AzurePIMTestResult -TestResult $result -FunctionName $MyInvocation.MyCommand
            switch ($result.ActionType) {
                "Create" {
                    try {
                        $requestMethod = "PUT"
                        $subscriptionId = Resolve-Subscription -InputReference $result.desiredConfiguration.subscriptionReference
                        $requestBody = @{
                            "properties" = @{
                                "roleName" = $result.DesiredConfiguration.roleName
                                "description" = $result.DesiredConfiguration.description
                                "assignableScopes" = $result.DesiredConfiguration.assignableScopes
                                "permissions" = $result.DesiredConfiguration.permissions
                            }
                        }
                        $requestBody = $requestBody | ConvertTo-Json -Depth 5
                        $guid = (New-Guid).Guid

                        Invoke-RestMethod -Method $requestMethod -Uri "$($script:apiBaseUrl)$($subscriptionId.trimStart("/"))/providers/Microsoft.Authorization/roleDefinitions/$($guid)?api-version=2018-01-01-preview" -Headers @{"Authorization" = "Bearer $($azureToken)"} -Body $requestBody -ContentType "application/json"  | Out-Null
                        Write-PSFMessage -Level Host -String "AzurePIM.Invoke.ActionCompleted" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, (Get-ActionColor -Action $result.ActionType), $result.ActionType
                    }
                    catch {
                        Write-PSFMessage -Level Error -String "AzurePIM.Invoke.ActionFailed" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, $result.ActionType
                        throw $_
                    }
                }
                "Update" {
                    try {
                        $requestMethod = "PUT"
                        $requestBody = @{
                            "properties" = @{
                                "roleName" = $result.DesiredConfiguration.roleName
                                "description" = $result.DesiredConfiguration.description
                                "assignableScopes" = $result.DesiredConfiguration.assignableScopes
                                "permissions" = $result.DesiredConfiguration.permissions
                            }
                        }
                        $requestBody = $requestBody | ConvertTo-Json -Depth 5

                        Invoke-RestMethod -Method $requestMethod -Uri "$($script:apiBaseUrl)$($result.AzureResource.id.trimStart("/"))?api-version=2018-01-01-preview" -Headers @{"Authorization" = "Bearer $($azureToken)"} -Body $requestBody -ContentType "application/json"  | Out-Null
                        Write-PSFMessage -Level Host -String "AzurePIM.Invoke.ActionCompleted" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, (Get-ActionColor -Action $result.ActionType), $result.ActionType
                    }
                    catch {
                        Write-PSFMessage -Level Error -String "AzurePIM.Invoke.ActionFailed" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, $result.ActionType
                        throw $_
                    }
                }
                "Delete" {
                    try {
                        $requestMethod = "DELETE"

                        Invoke-RestMethod -Method $requestMethod -Uri "$($script:apiBaseUrl)$($result.AzureResource.id.trimStart("/"))?api-version=2018-01-01-preview" -Headers @{"Authorization" = "Bearer $($azureToken)"}  | Out-Null
                        Write-PSFMessage -Level Host -String "AzurePIM.Invoke.ActionCompleted" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, (Get-ActionColor -Action $result.ActionType), $result.ActionType
                    }
                    catch {
                        Write-PSFMessage -Level Error -String "AzurePIM.Invoke.ActionFailed" -StringValues $result.Tenant, $result.ResourceType, $result.ResourceName, $result.ActionType
                        throw $_
                    }
                }
                "NoActionRequired" {}
                default {
                    Write-PSFMessage -Level Warning -String "AzurePIM.Invoke.ActionTypeUnknown" -StringValues $result.ActionType
                }    
            }
        }
    }
}