POWERSHELL / MICROSOFT.GRAPH.IDENTITY.SIGNINS
ProAdvancedRead-onlylow

Export Conditional Access policies

Export Microsoft Entra Conditional Access policies to JSON with PowerShell for policy inventory, review and migration preparation.

Pro generation after license validation · Review before running · Opselith does not connect to your tenant

What this PowerShell script does

Exports Conditional Access policies.

Requirements

  • JSON output path - Example: C:\Temp\report.json

Environment

  • Module: Microsoft.Graph.Identity.SignIns
  • Permissions: Policy.Read.All
  • Output: JSON report
  • Context: Microsoft Graph PowerShell
  • Risk: Low
Review before you run The full Pro script is generated by Opselith after license validation. Test outside production first.
NEXT STEP

Ready to generate

Configure Export Conditional Access policies in the Builder, review the generated PowerShell and run it yourself in your own PowerShell session.

More about this script

Why use this template?

Use this Pro PowerShell script when you need to export conditional access policies. It can be previewed in the Builder; Pro access is required to generate it for your own environment.

The template uses Microsoft.Graph.Identity.SignIns and requires Policy.Read.All. Output: JSON report. Level: Advanced. Action: Read-only. Risk: Low.

Review before running

The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.

Preview the script

  1. Open the template in the PowerShell Builder.
  2. Review the purpose, requirements, permissions, output and risk.
  3. Activate Pro when you are ready to generate the full script, then test it outside production.

Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Export Conditional Access policies →

How to use this result

Use this read-only export to capture Conditional Access policy definitions for review without changing policy state.

When this helps

  • Create a policy inventory before a Conditional Access review or tenant migration.
  • Compare policy state, assignments, grant controls and session controls outside the portal.

How to read the result

  • A policy definition shows configured assignments and controls; it does not prove the policy was evaluated for a specific sign-in.
  • Enabled, report-only and disabled policy states should be interpreted separately during review.

Things to check

  • Named locations and referenced directory objects can require separate exports if you need a fully resolved dependency inventory.
  • Do not treat a JSON backup as proof that a policy can be safely re-created unchanged in another tenant.

What to do next: Review disabled, report-only or unusually broad policies and validate referenced users, groups, apps and locations before any change.

Related tasks

Official references

Before you runModule, permissions, inputs, compatibility and script checks
OPS / SCRIPT DETAILS

Script details

Exports Conditional Access policies. Review these details before generating or running the script.

securityexportpermissionsentrapolicy
Generated here. Run by you.Opselith does not connect to your tenant or run PowerShell. After generating, review the script and run it in your own PowerShell session.

What it works with

Module: Microsoft.Graph.Identity.SignIns

Microsoft Graph PowerShell lets the script work with Microsoft Entra and Microsoft 365 data through Microsoft Graph.

Context: Microsoft Graph PowerShell

Compatibility: PowerShell 7 is the supported target for this cloud template.

Permissions and changes

Permissions: Policy.Read.All

Risk: Low

Read-only: designed to collect information without intentionally changing the target environment.

Changes: Read-only. The script reads data and does not intentionally change the target environment.

Inputs

  • JSON output path - Example: C:\Temp\report.json (Required)

What to expect

Output: JSON report

Expect a JSON file at the path you choose. Open it in a text editor or import it into the tool that needs the data.

Example: C:\Temp\report.json

This template is in the Pro library. Generating the full script requires eligible Pro or tester access. Opselith receives only the values needed to build the script; it does not connect to your tenant, run PowerShell or store the generated script. You review and run the result in your own PowerShell session.

Example use

Exports Conditional Access policies.

Enter the required values in the Builder, review the generated script and confirm the output before running it.

Before you run: Make sure your account has Policy.Read.All. Check that the Microsoft.Graph.Identity.SignIns PowerShell module is available and that you are using the supported PowerShell version. Review the generated script and output path, then test outside production first.
Script checksWhat has been verifiedQA reviewed
Static checksPassed
PSScriptAnalyzerPending
Real-world run testNot yet recorded
Last checkedNot yet recorded

Real-world run results are shown only after Opselith reviews and accepts a tester report.

Tester: report a result →
TEST STATUSWhat Opselith has checked

Last reviewed: 10 Sept 2026

PSScriptAnalyzer: Awaiting a release PSScriptAnalyzer gate that includes this script. No analyzer pass is claimed yet.

Pending or Not yet recorded means there is no accepted result on file yet. A passed analyzer check does not mean the script has been run in a real tenant.

PRACTICAL GUIDE

How to use this result

Use the JSON export as a readable configuration snapshot of Conditional Access policies for review, comparison and change planning.

When this helps

  • Capture policy state before a planned Conditional Access change.
  • Review which policies are enabled, disabled or in another configured state.
  • Compare Conditions, GrantControls and SessionControls between snapshots.

How to read the result

  • Each policy includes its ID, display name, state, timestamps and the nested conditions/control objects returned by Microsoft Graph.
  • The JSON is a configuration inventory; it does not simulate whether a specific sign-in would be allowed or blocked.

Things to check

  • Conditional Access behavior depends on the combined policy set and the sign-in context, not one policy in isolation.
  • Protect exported policy data because it can reveal security-control design and targeting details.
What to do next: Keep a dated baseline before major changes and review differences at the policy-object level rather than relying only on display names.