What it works with
Module: ActiveDirectory
Context: Windows PowerShell 5.1 · Active Directory
Compatibility: Windows PowerShell 5.1 with the ActiveDirectory module is the supported target for this template.
Exports Active Directory objects that have servicePrincipalName values, with one row per SPN, for Kerberos/service-account inventory and security review.
PRO PREVIEW · Generation after access validation · Review before running · No tenant access
Exports Active Directory objects that have servicePrincipalName values, with one row per SPN, for Kerberos/service-account inventory and security review.
Configure Export Active Directory objects with service principal names in the Builder, review the generated PowerShell and run it in your own environment.
Exports Active Directory objects that have servicePrincipalName values, with one row per SPN, for Kerberos/service-account inventory and security review. It is designed as a focused inventory step that you can review and retain locally.
The template uses ActiveDirectory and requires Read access to Active Directory objects and the servicePrincipalName attribute.. Output: CSV report.
Read the generated script before execution. Read-only describes the intended Opselith template behavior; your surrounding commands, environment and permissions remain your responsibility.
This is a Pro Preview template. Pro is not publicly for sale yet; existing authorized access can generate the script after server-side entitlement validation.
Exports Active Directory objects that have servicePrincipalName values, with one row per SPN, for Kerberos/service-account inventory and security review. Review these details before generating or running the script.
Module: ActiveDirectory
Context: Windows PowerShell 5.1 · Active Directory
Compatibility: Windows PowerShell 5.1 with the ActiveDirectory module is the supported target for this template.
Permissions: Directory read access
Risk: Low
Execution impact: Read-only. The script reads configuration or inventory data and does not intentionally create, update or remove objects.
Output: CSV report generated locally by the script.
This template is part of the Pro library. The full Pro script is generated by Opselith after server-side license validation; only the configuration values needed by this template are sent for generation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.
Exports Active Directory objects that have servicePrincipalName values, with one row per SPN, for Kerberos/service-account inventory and security review.
Enter the required values in the Builder, review the generated script and confirm the output before running it.
Runtime and community evidence change only after an external tester result is reviewed and accepted for release evidence.
Tester: report a result →Last reviewed: 27 Aug 2026
Analyzer evidence: Awaiting a release PSScriptAnalyzer gate that includes this script. No analyzer pass is claimed yet.
Pending and Not yet recorded are evidence states, not failures. Analyzer status does not imply runtime validation.