Why use this template?
Use this PowerShell template when you need to export application password credential metadata without secret values. It can be previewed in the Builder; Pro access is required to generate it for your own environment.
The template uses Microsoft.Graph.Applications and requires Application.Read.All. Output: CSV report. Level: Advanced. Action: Read-only. Risk: Low.
Review before running
The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Preview the script
- Open the template in the PowerShell Builder.
- Review the purpose, requirements, permissions, output and risk.
- Activate Pro when you are ready to generate the full script, then test it outside production.
Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Export Entra applications with password credentials →
How to use this result
Use this report to list password-credential metadata for application registrations without exposing secret values.
When this helps
- Create an application secret inventory before credential rotation or ownership review.
- Compare credential IDs and start/end dates across app registrations.
How to read the result
- Each row represents password-credential metadata such as KeyId, StartDateTime and EndDateTime; the secret value is not returned.
- Application password credentials belong to application registrations and are distinct from certificate credentials and service-principal credentials.
Things to check
- An unexpired credential is not proof that it is still used by an application.
- This general inventory is broader than the separate expiring-secret report and does not assess owner or dependency status.
What to do next: Prioritize credentials nearing expiry and validate application ownership and dependencies before rotation or removal.
Related tasks
Official references