PowerShell automation scripts for Microsoft Entra ID identity lifecycle management, built using the Microsoft Graph PowerShell SDK.
This repository is a growing library of production-ready IAM automation scripts built for real-world Entra ID environments. Scripts follow least-privilege principles, include full audit logging, and support -WhatIf for safe pre-flight testing.
Built by CJ. Williams
| Component | Version |
|---|---|
| PowerShell | 7.6.3 |
| Microsoft Graph SDK | 2.38.0 |
| Platform | Ubuntu 22.04 LTS |
| Identity Platform | Microsoft Entra ID |
curl -sSL https://packages.microsoft.com/keys/microsoft.asc | sudo tee /etc/apt/trusted.gpg.d/microsoft.asc
curl -sSL https://packages.microsoft.com/config/ubuntu/22.04/prod.list | sudo tee /etc/apt/sources.list.d/microsoft-prod.list
sudo apt update && sudo apt install -y powershellInstall-Module Microsoft.Graph -Scope CurrentUser -ForceConnect-MgGraph -Scopes "User.ReadWrite.All","Directory.ReadWrite.All","AuditLog.Read.All" -TenantId "your-tenant-id" -UseDeviceAuthenticationProvisions a new user in Microsoft Entra ID via Microsoft Graph.
Features:
- Auto-derives UPN and display name from first/last name and tenant domain
- Generates a secure 16-character temporary password
- Prompts interactively if user already exists
- Full audit logging to
logs/ -WhatIfsupport for pre-flight testing
Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All
Usage:
# Dry run
.\scripts\New-EntraUser.ps1 -FirstName "Jane" -LastName "Smith" -Department "Finance" -JobTitle "Analyst" -WhatIf
# Live run
.\scripts\New-EntraUser.ps1 -FirstName "Jane" -LastName "Smith" -Department "Finance" -JobTitle "Analyst"Performs structured six-step offboarding of an Entra ID user.
Offboarding Steps:
- Disable account — blocks sign-in immediately
- Revoke all active sessions — invalidates live tokens
- Remove group memberships — strips resource access
- Remove directory role assignments — strips admin privileges
- Hide from Global Address List — removes from email directory
- Delete user — choice of soft delete (30-day recovery) or permanent delete
Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All
Usage:
# Dry run
.\scripts\Remove-EntraUser.ps1 -UserPrincipalName "jane.smith@contoso.onmicrosoft.com" -WhatIf
# Live run
.\scripts\Remove-EntraUser.ps1 -UserPrincipalName "jane.smith@contoso.onmicrosoft.com"Identifies inactive Entra ID accounts based on last sign-in activity.
Features:
- Configurable inactivity threshold (default: 90 days)
- Filters for guest accounts and disabled accounts
- Exports findings to timestamped CSV in
logs/ - Interactive per-account action prompt — disable, skip, or skip all
-WhatIfsupport for pre-flight testing
Required Scopes: User.Read.All, AuditLog.Read.All, Directory.Read.All
License Requirement: Microsoft Entra ID P1 or P2 (for SignInActivity data)
Usage:
# Default 90-day threshold, dry run
.\scripts\Get-StaleAccounts.ps1 -WhatIf
# 30-day threshold, exclude guests and disabled accounts
.\scripts\Get-StaleAccounts.ps1 -DaysInactive 30 -ExcludeGuests -ExcludeDisabled
# Live run with custom threshold
.\scripts\Get-StaleAccounts.ps1 -DaysInactive 60Generates an access report showing group memberships and directory role assignments for one or all users.
Features:
- Single user mode — detailed breakdown of groups and roles for a specific UPN
- Full tenant mode — summary table of all active users with group and role counts
- Exports findings to timestamped CSV in
logs/ -WhatIfsupport for pre-flight testing
Required Scopes: User.Read.All, Directory.Read.All, RoleManagement.Read.Directory
Usage:
# Single user detailed report
.\scripts\Get-UserAccessReport.ps1 -UserPrincipalName "admin@contoso.onmicrosoft.com"
# Full tenant report
.\scripts\Get-UserAccessReport.ps1
# Include disabled accounts
.\scripts\Get-UserAccessReport.ps1 -IncludeDisabledAudits and reports all Conditional Access policies in Microsoft Entra ID.
Features:
- Summary table of all policies with state, targets, and grant controls
- Detailed per-policy breakdown including users, groups, apps, conditions, and session controls
- Resolves GUIDs to display names — flags unresolvable objects as potential misconfigurations
- Configurable output format — console, CSV, or both
- Filter by policy state — All, Enabled, Disabled, or ReportOnly
-WhatIfsupport for pre-flight testing
Required Scopes: Policy.Read.All, Directory.Read.All
Usage:
# Full report - console and CSV
.\scripts\Get-ConditionalAccessReport.ps1
# Enabled policies only, console output only
.\scripts\Get-ConditionalAccessReport.ps1 -PolicyState Enabled -OutputFormat ConsoleOnly
# CSV export only
.\scripts\Get-ConditionalAccessReport.ps1 -OutputFormat CSVOnly
# Dry run
.\scripts\Get-ConditionalAccessReport.ps1 -WhatIfBulk provisions Entra ID users from a CSV file via Microsoft Graph.
Features:
- Validates CSV structure before processing — fails fast on missing columns
- Handles spaces in names automatically — strips from UPN, preserves in display name
- Interactive duplicate handling — prompt per user or auto-skip with
-SkipDuplicates - Exports timestamped results CSV with temp passwords and status per user
- Progress bar shows real-time processing status
-WhatIfsupport for pre-flight testing
Required Scopes: User.ReadWrite.All, Directory.ReadWrite.All
CSV Format:
FirstName,LastName,Department,JobTitle,UsageLocation
John,Doe,IT,Help Desk Analyst,USUsage:
# Interactive mode
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv"
# Auto-skip duplicates
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv" -SkipDuplicates
# Dry run
.\scripts\Import-EntraUsersFromCsv.ps1 -CsvPath "./samples/bulk-users-template.csv" -WhatIf| Script | Description | Status |
|---|---|---|
New-EntraUser.ps1 |
Interactive user provisioning with loop | ✅ Complete |
Remove-EntraUser.ps1 |
Six-step structured offboarding | ✅ Complete |
Get-StaleAccounts.ps1 |
Stale account detection with CSV export | ✅ Complete |
Get-UserAccessReport.ps1 |
User role and group membership reporting | ✅ Complete |
Get-ConditionalAccessReport.ps1 |
Audit and report Conditional Access policies | ✅ Complete |
Import-EntraUsersFromCsv.ps1 |
Bulk user provisioning from CSV | ✅ Complete |
AI Access Review Summarizer |
Python + Azure OpenAI access review summaries | Planned |
Stale Access Anomaly Detector |
PowerShell + Azure OpenAI anomaly detection | Planned |
entra-iam-scripts/
├── scripts/ # PowerShell automation scripts
├── samples/ # CSV templates and sample input files
├── logs/ # Audit logs and CSV reports (git ignored)
├── docs/ # Additional documentation
└── .gitignore # Excludes logs and credentials