OPS / SCRIPT DETAILS
Script details
Finds groups that are both mail-enabled and security-enabled. Review these details before generating or running the script.
entrafindgroupssecurity
Generated here. Run by you.Opselith does not connect to your tenant or run PowerShell. After generating, review the script and run it in your own PowerShell session.
What it works with
Module: Microsoft.Graph.Groups
Microsoft Graph PowerShell lets the script work with Microsoft Entra and Microsoft 365 data through Microsoft Graph.
Context: PowerShell 7 · Microsoft Graph
Compatibility: PowerShell 7 is the supported target for this Microsoft 365 template.
Permissions and changes
Permissions: Group.Read.All
Risk: Low
Read-only: designed to collect information without intentionally changing the target environment.
Changes: Read-only. The script reads data and does not intentionally change the target environment.
Inputs
- CSV output path - Example: C:\Temp\report.csv (Required)
What to expect
Output: CSV report
Expect a CSV file at the path you choose. Open it in Excel or another CSV viewer and review the rows.
Example: C:\Temp\report.csvThis template is in the Free library and is generated locally in your browser. Opselith does not run it; you review and run the script in your own PowerShell session.
Example use
Finds groups that are both mail-enabled and security-enabled.
Enter the required values in the Builder, review the generated script and confirm the output before running it.
Before you run: Make sure your account has Group.Read.All. Check that the Microsoft.Graph.Groups PowerShell module is available and that you are using the supported PowerShell version. Review the generated script and output path, then test outside production first.
Script checksWhat has been verifiedQA reviewed
Static checksPassed
PSScriptAnalyzerPending
Real-world run testNot yet recorded
Last checkedNot yet recorded
TEST STATUSWhat Opselith has checkedLast reviewed: 10 Sept 2026
PSScriptAnalyzer: Awaiting a release PSScriptAnalyzer gate that includes this script. No analyzer pass is claimed yet.
Pending or Not yet recorded means there is no accepted result on file yet. A passed analyzer check does not mean the script has been run in a real tenant.