No tenant connection
The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.
Combine a small set of useful read-only Microsoft 365 checks without deep tenant-wide security correlation.
This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.
Opselith does not execute these steps against your environment. Script steps open a reviewed Opselith template; change steps remain explicit so nothing is hidden behind a browser action.
Capture disabled member and guest users as a basic identity-state check.
Open Export disabled Entra users →Check subscribed SKUs and consumed units for obvious capacity pressure.
Open Export tenant license SKUs →Inspect archive status and quota properties for Exchange Online mailboxes.
Open Export mailbox archive status →Export mailbox size and item-count information for basic service-health context.
Open Export mailbox sizes →Identify Teams where no owner is returned by the current Teams membership view.
Open Find Teams without owners →Review managed devices currently reported as non-compliant.
Open Find non-compliant Intune devices →Use the outputs as a bounded health snapshot. This is not a security certification or a replacement for workload-specific monitoring.
The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.
Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.
Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.
Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.
Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.
A guided workflow is not itself a PowerShell artifact.
No accepted runtime result is recorded for this workflow yet.
browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.
Trust metadata reviewed for the current 3.0 development contract.
6 referenced scripts · 6 analyzer Passed · 0 Pending
Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.
Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.