OPS / POWERSHELL LIBRARY

Microsoft Entra PowerShell scripts

Use these Microsoft Entra templates to inspect identities, groups, roles, devices, authentication registration, Conditional Access, sign-in activity and enterprise applications through Microsoft Graph. Each script page states its Graph modules, delegated permissions, runtime and output before generation.

32Scripts16Free16Pro
HOW TO USE THIS COLLECTION

Start with the task, then review the requirements.

Every linked script page documents its runtime, modules, permissions, inputs, output, action and risk before you generate anything.

Microsoft Graph permissionsGraph scopes vary by task. Review the permissions on the individual script page instead of granting one broad scope to every template.
Modern PowerShell routeThe Entra collection uses the Microsoft Graph PowerShell SDK and follows the PowerShell 7 runtime guidance documented per template.
Interpret identity signals carefullySign-in, guest-age, device and secret reports expose the state Microsoft Graph provides; missing or stale values are kept explicit instead of being converted into certainty.
01 / COLLECTION

Users, guests & authentication

12 focused templates with individual runtime, permission, risk, input and output guidance.

PROAdvanced · Low risk

Export Entra risky users

Exports Microsoft Entra Identity Protection risky-user state, risk level/detail and last risk update from the stable Microsoft Graph v1.0 riskyUsers API.

Read-onlyMicrosoft Entra
Review script details →
02 / COLLECTION

Groups & directory roles

9 focused templates with individual runtime, permission, risk, input and output guidance.

03 / COLLECTION

Devices & sign-in activity

3 focused templates with individual runtime, permission, risk, input and output guidance.

04 / COLLECTION

Enterprise applications & secrets

6 focused templates with individual runtime, permission, risk, input and output guidance.

05 / COLLECTION

Tenant policy & licensing

2 focused templates with individual runtime, permission, risk, input and output guidance.

POWERSHELL COLLECTIONS

Browse another workload.

Move between workload collections without returning to the full 135-script library.

BUILD / REVIEW / RUN

Generate from the PowerShell Builder.

Opselith does not execute these scripts against your tenant. Generate, review and run them in your own PowerShell environment.