Export-IntunePolicies.ps1
Exports Intune configuration, compliance, administrative template and platform script policies to JSON for backup and documentation.
28 documented PowerShell scripts from day-to-day consulting work — the questions admins ask most often ("which devices stopped syncing?", "who forwards mail outside the company?", "which teams are dead?") turned into repeatable, read-only-by-default tools built on Microsoft Graph and Exchange Online PowerShell V3.
Showing all 28 scripts
Export-IntunePolicies.ps1Exports Intune configuration, compliance, administrative template and platform script policies to JSON for backup and documentation.
Get-AutopilotDeviceReport.ps1Windows Autopilot registration health report: profile assignment status, enrollment state and last contact per device.
Get-IntuneAppInstallStatus.ps1Install status overview (installed / failed / pending / not applicable) for every assigned Intune app.
Get-IntuneDefenderAVStatus.ps1Microsoft Defender Antivirus health report for Intune-managed Windows devices.
Get-IntuneDeviceComplianceReport.ps1Inventory and compliance report for all Intune managed devices.
Get-IntunePolicyAssignments.ps1Builds a "who gets what" assignment matrix for Intune policies and (optionally) apps.
Get-IntuneStaleDevices.ps1Reports Intune managed devices that have not synced for a given number of days and can optionally retire or delete them.
Invoke-IntuneDeviceSync.ps1Sends a bulk Intune "Sync" remote action to managed devices selected by name, platform, Entra group or all devices.
Export-EntraConditionalAccessPolicies.ps1Backs up every Conditional Access policy to JSON and builds a human-readable CSV summary.
Get-EntraAppCredentialExpiry.ps1Reports app registration client secrets and certificates that are expired or expiring soon.
Get-EntraMFARegistrationReport.ps1Reports the MFA, passwordless and SSPR registration posture of users in Microsoft Entra ID.
Get-EntraPrivilegedRoleMembers.ps1Reports who holds Microsoft Entra directory roles, including active assignments and PIM-eligible assignments.
Get-EntraStaleGuestUsers.ps1Finds guest accounts that never signed in, have been inactive for a number of days, or never accepted their invitation.
Get-DefenderAlertsReport.ps1Reports alerts from Microsoft Defender XDR (unified alerts API) for the last N days.
Get-DefenderIncidentsReport.ps1Reports Microsoft Defender XDR incidents for triage, including how long each one has been open.
Get-DefenderSecureScore.ps1Shows the current Microsoft Secure Score and the improvement actions with the largest remaining point gap.
Get-EXOExternalForwardingReport.ps1Finds mail leaving the tenant through mailbox forwarding or inbox rules, and optionally removes it.
Get-EXOMailboxPermissionsReport.ps1Audits delegated mailbox access: FullAccess, SendAs and SendOnBehalf grants across Exchange Online mailboxes.
Get-EXOMailboxSizeReport.ps1Reports mailbox and archive size, item counts and quota usage for Exchange Online mailboxes.
Export-PurviewDLPPolicies.ps1Documents Microsoft Purview DLP policies and their rules to CSV and JSON.
Export-PurviewSensitivityLabels.ps1Documents Microsoft Purview sensitivity labels and label policies to CSV and JSON.
Search-PurviewAuditLog.ps1Exports unified audit log records reliably, beyond the 5,000-row limit of a single Search-UnifiedAuditLog call.
Get-SPOSiteStorageReport.ps1Reports SharePoint Online storage consumption per site and flags dormant sites, optionally including OneDrive.
Get-TeamsGuestAccessReport.ps1Reports which Microsoft Teams teams contain guest users and which external domains they come from.
Get-TeamsInactiveTeams.ps1Finds Microsoft Teams teams that nobody uses, based on the Teams team activity usage report.
Get-M365LicenseReport.ps1Reports Microsoft 365 license consumption per SKU and, optionally, licensed users whose licenses could be reclaimed.
Get-M365ServiceHealthReport.ps1Reports current Microsoft 365 service incidents and advisories and, optionally, Message Center changes that need action.
Install-Prerequisites.ps1Installs or updates the PowerShell modules required by the scripts in this repository.
A script only changes something when you pass an explicit switch such as -RetireDevices or -Remediate. Every change supports -WhatIf and -Confirm.
Each script requests only the Graph scopes or Exchange roles it needs and lists them in its help and in the folder README.
Microsoft Graph PowerShell SDK (v1.0 where possible) and Exchange Online PowerShell V3. No retired AzureAD or MSOnline modules.
No PowerShell 7-only syntax, so the scripts run wherever your admins already work.
Get-Help .\Script.ps1 -Full works everywhere. Reports land in .\Reports\ as timestamped CSV files; add -PassThru to keep working with the objects.
Every script passes PSScriptAnalyzer with the repository's settings before it is published.
Before you run anything: read the script's help (Get-Help .\Script.ps1 -Full), check the permissions it requests, and try it in a test tenant or with -WhatIf first. The scripts are published under the MIT licence — use them, adapt them, and send improvements back through GitHub.
Tell me which report or clean-up task you'd like automated, and it may become the next addition to the repository.