ADMIN WORKFLOW / FREEFREE WORKFLOW

User Onboarding

Prepare and complete a bounded user onboarding workflow with explicit prerequisites, checks and locally generated PowerShell steps.

Read + manual change steps8 guided stepsActive Directory · Microsoft Entra · Exchange Online
WHEN TO USE IT

Use this workflow when the job is clear and bounded.

This guide is designed for a single administrative task rather than a broad tenant-wide assessment. It keeps discovery, preparation, any manual change and final verification separate so you can review each step before moving on.

Create user with validated identity fieldsSet core identity attributesAdd approved group membershipsAssign a selected Microsoft 365 licenseOptional mailbox/bootstrap checks
RUNBOOK

The workflow, in order.

Opselith does not execute these steps against your environment. Script steps open a reviewed Opselith template; change steps remain explicit so nothing is hidden behind a browser action.

  1. 01 · PREPARE

    Confirm the onboarding request

    Confirm the approved identity, manager, department, start date, group and license requirements in your normal ticket or change record. Do not enter those values into this runbook.

  2. 02 · SCRIPT

    Review existing enabled AD users

    Use the Free inventory script to check naming patterns and reduce the chance of creating a duplicate identity.

    Open Export enabled AD users →
  3. 03 · SCRIPT

    Review approved AD group targets

    Find the approved Active Directory groups before any membership change is made.

    Open Find AD groups →
  4. 04 · SCRIPT

    Review Entra group types

    Confirm whether cloud groups are security, Microsoft 365, mail-enabled or dynamic before assigning access.

    Open Export Entra group types →
  5. 05 · ACTION

    Create the identity in your approved admin path

    Create the user with your normal AD or Entra administration process. Opselith does not connect to the tenant or execute this change.

  6. 06 · SCRIPT

    Review Microsoft 365 license capacity

    Check subscribed SKUs and consumed units before assigning the approved license.

    Open Export tenant license SKUs →
  7. 07 · ACTION

    Assign approved groups and license

    Apply only the memberships and license approved in the onboarding request, then allow required services to provision.

  8. 08 · VERIFY

    Verify the finished onboarding

    Confirm sign-in state, expected group access, licensing and service provisioning in the authoritative admin portals before closing the request.

PRIVACY & CONTROL

Your tenant stays outside Opselith.

No tenant connection

The workflow itself never signs in to Active Directory or Microsoft 365. Any generated PowerShell runs only after you review and execute it locally.

Local progress only

Completed workflow step IDs can be stored in your browser. Identity values, tickets, usernames, domains and generated output are not part of that progress record.

Manual changes stay manual

Where no suitable reviewed script exists, the guide labels the action as a manual change rather than pretending the website performed it.

TRUST / EVIDENCE

Recorded trust facts, not a certification.

Opselith separates metadata review, static QA, analyzer evidence and runtime evidence. A missing runtime result or a Pending analyzer state is shown as-is rather than converted into a pass claim.

Static QAPassed

Workflow catalog, ordered runbook, local-progress and manual-change boundary QA.

PSScriptAnalyzerNot applicable

A guided workflow is not itself a PowerShell artifact.

Runtime evidenceNot yet recorded

No accepted runtime result is recorded for this workflow yet.

Execution boundaryRead + explicit manual change steps

browser-guided-runbook · no website tenant connection · tenant output stays outside Opselith.

Last reviewed28 Aug 2026

Trust metadata reviewed for the current 3.0 development contract.

Referenced scripts4

4 referenced scripts · 4 analyzer Passed · 0 Pending

Pending and Not yet recorded are evidence states, not failures. Review the generated script or runbook and validate it in your own environment before production use.

RELATED POWERSHELL

Scripts used by this workflow.

BEFORE YOU CLOSE THE JOB

Verify in the authoritative admin tools.

Use the final verification step to confirm the resulting account, membership, licensing or service state in the relevant Microsoft administration portal or Active Directory tooling. Opselith is a runbook and script-generation layer, not the system of record.