Skip to content

About

PowerShell automation scripts for Microsoft Entra ID identity lifecycle management

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

17 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

entra-iam-scripts

PowerShell automation scripts for Microsoft Entra ID identity lifecycle management, built using the Microsoft Graph PowerShell SDK.

About

This repository is a growing library of production-ready IAM automation scripts built for real-world Entra ID environments. Scripts follow least-privilege principles, include full audit logging, and support -WhatIf for safe pre-flight testing.

Built by CJ. Williams


Environment

Component Version
PowerShell 7.6.3
Microsoft Graph SDK 2.38.0
Platform Ubuntu 22.04 LTS
Identity Platform Microsoft Entra ID

Prerequisites

1. Install PowerShell 7

curl -sSL https://packages.microsoft.com/keys/microsoft.asc | sudo tee /etc/apt/trusted.gpg.d/microsoft.asc
curl -sSL https://packages.microsoft.com/config/ubuntu/22.04/prod.list | sudo tee /etc/apt/sources.list.d/microsoft-prod.list
sudo apt update && sudo apt install -y powershell

2. Install Microsoft Graph SDK

Install-Module Microsoft.Graph -Scope CurrentUser -Force

3. Connect to your Entra ID tenant

Connect-MgGraph -Scopes "User.ReadWrite.All","Directory.ReadWrite.All","AuditLog.Read.All" -TenantId "your-tenant-id" -UseDeviceAuthentication

Script Library

New-EntraUser.ps1

Provisions a new user in Microsoft Entra ID via Microsoft Graph.

Features:

  • Auto-derives UPN and display name from first/last name and tenant domain
  • Generates a secure 16-character temporary password
  • Prompts interactively if user already exists
  • Full audit logging to logs/
  • -WhatIf support for pre-flight testing

Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All

Usage:

# Dry run
.\scripts\New-EntraUser.ps1 -FirstName "Jane" -LastName "Smith" -Department "Finance" -JobTitle "Analyst" -WhatIf

# Live run
.\scripts\New-EntraUser.ps1 -FirstName "Jane" -LastName "Smith" -Department "Finance" -JobTitle "Analyst"

Remove-EntraUser.ps1

Performs structured six-step offboarding of an Entra ID user.

Offboarding Steps:

  1. Disable account — blocks sign-in immediately
  2. Revoke all active sessions — invalidates live tokens
  3. Remove group memberships — strips resource access
  4. Remove directory role assignments — strips admin privileges
  5. Hide from Global Address List — removes from email directory
  6. Delete user — choice of soft delete (30-day recovery) or permanent delete

Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All

Usage:

# Dry run
.\scripts\Remove-EntraUser.ps1 -UserPrincipalName "jane.smith@contoso.onmicrosoft.com" -WhatIf

# Live run
.\scripts\Remove-EntraUser.ps1 -UserPrincipalName "jane.smith@contoso.onmicrosoft.com"

Get-StaleAccounts.ps1

Identifies inactive Entra ID accounts based on last sign-in activity.

Features:

  • Configurable inactivity threshold (default: 90 days)
  • Filters for guest accounts and disabled accounts
  • Exports findings to timestamped CSV in logs/
  • Interactive per-account action prompt — disable, skip, or skip all
  • -WhatIf support for pre-flight testing

Required Scopes: User.Read.All, AuditLog.Read.All, Directory.Read.All

License Requirement: Microsoft Entra ID P1 or P2 (for SignInActivity data)

Usage:

# Default 90-day threshold, dry run
.\scripts\Get-StaleAccounts.ps1 -WhatIf

# 30-day threshold, exclude guests and disabled accounts
.\scripts\Get-StaleAccounts.ps1 -DaysInactive 30 -ExcludeGuests -ExcludeDisabled

# Live run with custom threshold
.\scripts\Get-StaleAccounts.ps1 -DaysInactive 60

Get-UserAccessReport.ps1

Generates an access report showing group memberships and directory role assignments for one or all users.

Features:

  • Single user mode — detailed breakdown of groups and roles for a specific UPN
  • Full tenant mode — summary table of all active users with group and role counts
  • Exports findings to timestamped CSV in logs/
  • -WhatIf support for pre-flight testing

Required Scopes: User.Read.All, Directory.Read.All, RoleManagement.Read.Directory

Usage:

# Single user detailed report
.\scripts\Get-UserAccessReport.ps1 -UserPrincipalName "admin@contoso.onmicrosoft.com"

# Full tenant report
.\scripts\Get-UserAccessReport.ps1

# Include disabled accounts
.\scripts\Get-UserAccessReport.ps1 -IncludeDisabled

Get-ConditionalAccessReport.ps1

Audits and reports all Conditional Access policies in Microsoft Entra ID.

Features:

  • Summary table of all policies with state, targets, and grant controls
  • Detailed per-policy breakdown including users, groups, apps, conditions, and session controls
  • Resolves GUIDs to display names — flags unresolvable objects as potential misconfigurations
  • Configurable output format — console, CSV, or both
  • Filter by policy state — All, Enabled, Disabled, or ReportOnly
  • -WhatIf support for pre-flight testing

Required Scopes: Policy.Read.All, Directory.Read.All

Usage:

# Full report - console and CSV
.\scripts\Get-ConditionalAccessReport.ps1

# Enabled policies only, console output only
.\scripts\Get-ConditionalAccessReport.ps1 -PolicyState Enabled -OutputFormat ConsoleOnly

# CSV export only
.\scripts\Get-ConditionalAccessReport.ps1 -OutputFormat CSVOnly

# Dry run
.\scripts\Get-ConditionalAccessReport.ps1 -WhatIf

Import-EntraUsersFromCsv.ps1

Bulk provisions Entra ID users from a CSV file via Microsoft Graph.

Features:

  • Validates CSV structure before processing — fails fast on missing columns
  • Handles spaces in names automatically — strips from UPN, preserves in display name
  • Interactive duplicate handling — prompt per user or auto-skip with -SkipDuplicates
  • Exports timestamped results CSV with temp passwords and status per user
  • Progress bar shows real-time processing status
  • -WhatIf support for pre-flight testing

Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All

CSV Format:

FirstName,LastName,Department,JobTitle,UsageLocation
John,Doe,IT,Help Desk Analyst,US

Usage:

# Interactive mode
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv"

# Auto-skip duplicates
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv" -SkipDuplicates

# Dry run
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv" -WhatIf

Planned Scripts

Script Description Status
New-EntraUser.ps1 Interactive user provisioning with loop ✅ Complete
Remove-EntraUser.ps1 Six-step structured offboarding ✅ Complete
Get-StaleAccounts.ps1 Stale account detection with CSV export ✅ Complete
Get-UserAccessReport.ps1 User role and group membership reporting ✅ Complete
Get-ConditionalAccessReport.ps1 Audit and report Conditional Access policies ✅ Complete
Import-EntraUsersFromCsv.ps1 Bulk user provisioning from CSV ✅ Complete
AI Access Review Summarizer Python + Azure OpenAI access review summaries Planned
Stale Access Anomaly Detector PowerShell + Azure OpenAI anomaly detection Planned

Repository Structure

entra-iam-scripts/
├── scripts/          # PowerShell automation scripts
├── samples/          # CSV templates and sample input files
├── logs/             # Audit logs and CSV reports (git ignored)
├── docs/             # Additional documentation
└── .gitignore        # Excludes logs and credentials

About

PowerShell automation scripts for Microsoft Entra ID identity lifecycle management

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages