POWERSHELL / MICROSOFT.GRAPH.USERS
FreeBeginnerRead-onlylow

Export disabled Entra users

Export currently disabled Microsoft Entra users to CSV with PowerShell for account lifecycle and access review.

Generated locally in your browser · Review before running · Opselith does not connect to your tenant

What this PowerShell script does

Exports disabled Entra member and guest users

Requirements

    Environment

    • Module: Microsoft.Graph.Users
    • Permissions: User.Read.All
    • Output: CSV report
    • Context: Microsoft Graph PowerShell
    • Risk: Low
    Review before you run The script is generated locally. Test outside production first.
    NEXT STEP

    Ready to generate

    Configure Export disabled Entra users in the Builder, review the generated PowerShell and run it yourself in your own PowerShell session.

    More about this script

    Why use this template?

    Use this free PowerShell script when you need to export disabled entra member and guest users. It is generated locally and can be reviewed before you run it yourself in your own PowerShell session.

    The template uses Microsoft.Graph.Users and requires User.Read.All. Output: CSV report. Level: Beginner. Action: Read-only. Risk: Low.

    Review before running

    The script is generated in your browser. Read it before you run it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.

    Generate the script

    1. Open the template in the PowerShell Builder.
    2. Enter the requested values and review the module, permissions, output and risk.
    3. Generate the script, read it carefully, and test it outside production before use.

    The script is generated locally in your browser. Nothing needs to be uploaded to Opselith.

    Generate Export disabled Entra users →

    How to use this result

    Use this report to inventory users whose current AccountEnabled value is false without changing the accounts.

    When this helps

    • Review disabled accounts during offboarding, access reviews or directory cleanup.
    • Compare account type, created date, UPN and email before deciding whether follow-up is needed.

    How to read the result

    • A returned row means AccountEnabled is currently false at query time.
    • The report does not show when or why the account was disabled, who changed it or whether downstream data should be removed.

    Things to check

    • Disabled does not automatically mean obsolete; retained accounts can still be needed for legal, mailbox, ownership or investigation reasons.
    • Use audit history and workload ownership for high-impact lifecycle decisions.

    What to do next: Confirm ownership, retention requirements and disable history before deleting or otherwise changing a returned account.

    Related tasks

    Official references

    Before you runModule, permissions, inputs, compatibility and script checks
    OPS / SCRIPT DETAILS

    Script details

    Exports disabled Entra member and guest users Review these details before generating or running the script.

    entraexportusersguestsdisabled
    Generated here. Run by you.Opselith does not connect to your tenant or run PowerShell. After generating, review the script and run it in your own PowerShell session.

    What it works with

    Module: Microsoft.Graph.Users

    Microsoft Graph PowerShell lets the script work with Microsoft Entra and Microsoft 365 data through Microsoft Graph.

    Context: Microsoft Graph PowerShell

    Compatibility: PowerShell 7 is the supported target for this cloud template.

    Permissions and changes

    Permissions: User.Read.All

    Risk: Low

    Read-only: designed to collect information without intentionally changing the target environment.

    Changes: Read-only. The script reads data and does not intentionally change the target environment.

    Inputs

    • CSV output path - Example: C:\Temp\report.csv (Required)

    What to expect

    Output: CSV report

    Expect a CSV file at the path you choose. Open it in Excel or another CSV viewer and review the rows.

    Example: C:\Temp\report.csv

    This template is in the Free library and is generated locally in your browser. Opselith does not run it; you review and run the script in your own PowerShell session.

    Example use

    Exports disabled Entra member and guest users

    Enter the required values in the Builder, review the generated script and confirm the output before running it.

    Before you run: Make sure your account has User.Read.All. Check that the Microsoft.Graph.Users PowerShell module is available and that you are using the supported PowerShell version. Review the generated script and output path, then test outside production first.
    Script checksWhat has been verifiedQA reviewed
    Static checksPassed
    PSScriptAnalyzerPending
    Real-world run testNot yet recorded
    Last checkedNot yet recorded

    Real-world run results are shown only after Opselith reviews and accepts a tester report.

    Tester: report a result →
    TEST STATUSWhat Opselith has checked

    Last reviewed: 28 Aug 2026

    PSScriptAnalyzer: Awaiting a release PSScriptAnalyzer gate that includes this script. No analyzer pass is claimed yet.

    Pending or Not yet recorded means there is no accepted result on file yet. A passed analyzer check does not mean the script has been run in a real tenant.