Why use this template?
Use this Pro PowerShell script when you need to export conditional access policies. It can be previewed in the Builder; Pro access is required to generate it for your own environment.
The template uses Microsoft.Graph.Identity.SignIns and requires Policy.Read.All. Output: JSON report. Level: Advanced. Action: Read-only. Risk: Low.
Review before running
The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Preview the script
- Open the template in the PowerShell Builder.
- Review the purpose, requirements, permissions, output and risk.
- Activate Pro when you are ready to generate the full script, then test it outside production.
Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Export Conditional Access policies →
How to use this result
Use this read-only export to capture Conditional Access policy definitions for review without changing policy state.
When this helps
- Create a policy inventory before a Conditional Access review or tenant migration.
- Compare policy state, assignments, grant controls and session controls outside the portal.
How to read the result
- A policy definition shows configured assignments and controls; it does not prove the policy was evaluated for a specific sign-in.
- Enabled, report-only and disabled policy states should be interpreted separately during review.
Things to check
- Named locations and referenced directory objects can require separate exports if you need a fully resolved dependency inventory.
- Do not treat a JSON backup as proof that a policy can be safely re-created unchanged in another tenant.
What to do next: Review disabled, report-only or unusually broad policies and validate referenced users, groups, apps and locations before any change.
Related tasks
Official references