Why use this template?
Use this Pro PowerShell script when you need to export directory role assignments. It can be previewed in the Builder; Pro access is required to generate it for your own environment.
The template uses Microsoft.Graph.Identity.Governance and requires RoleManagement.Read.Directory. Output: CSV report. Level: Advanced. Action: Read-only. Risk: Low.
Review before running
The script remains preview-only until Pro access is enabled. Review it before running it, and test it outside production first. “Read-only” describes the script itself; anything you add around it can still change data.
Preview the script
- Open the template in the PowerShell Builder.
- Review the purpose, requirements, permissions, output and risk.
- Activate Pro when you are ready to generate the full script, then test it outside production.
Pro templates remain previewable before purchase or activation. No tenant connection is required. When you generate a Pro script, only the configuration values needed for that template are sent to Opselith after license validation.Preview Export Entra admin role assignments →
How to use this result
Use this report to inventory current directory role assignments and their assignment IDs for privileged-access review.
When this helps
- Create an admin-role assignment inventory before a privileged-access review.
- Trace a current role assignment back to its assignment, principal and role-definition identifiers.
How to read the result
- A role assignment links a principal to a role definition at a directory scope; '/' normally represents tenant-wide directory scope.
- This report covers current role assignments, not PIM eligibility schedules or historical activation events.
Things to check
- Role assignments can target users, groups or service principals, so principal type and ownership matter during review.
- Application-scoped and administrative-unit-scoped assignments need their scope interpreted in context.
What to do next: Review broad or unexpected assignments with the role owner and compare them with PIM eligibility before changing access.
Related tasks
Official references