No tenant connection
The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.
Review common Entra identity hygiene signals across guests, authentication registration and core account metadata.
This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.
Start with the first step. Open later steps only when you need them; all guidance remains on this page and remains crawlable.
Export guest users so external identities can be reviewed against current business ownership and access needs.
Open Export Entra guest users →Capture authentication registration status and identify accounts that need follow-up under your organisation's authentication policy.
Open Export Entra authentication registration status →Identify accounts missing usage location where that attribute is required for licensing or service configuration.
Open Find Entra users without usage location →Review missing department values where your organisation uses them for administration, grouping or lifecycle processes.
Open Find Entra users without department →Review missing job-title values where that metadata supports administration or access review.
Open Find Entra users without job title →Identify Entra users without a mail value and confirm whether each missing value is expected for that account type.
Open Find Entra users without mail →Classify the findings in context before changing directory attributes. Missing metadata is a review signal and not automatically an error.
The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.
Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.
Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.
Recorded trust facts, not a certification. Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.
Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.
A guided workflow is not itself a PowerShell artifact.
No accepted runtime result is recorded for this workflow yet.
browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.
Trust metadata reviewed for the current release contract.
6 referenced scripts · 6 analyzer Passed · 0 Pending
Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.
Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.