Get notified the moment someone joins your Global Admins or a Tier 0 access group. Part 1 of a two-part series builds an Azure Function App that consumes Microsoft Graph change notifications, validates the webhook, and posts Teams alerts on every membership change.
Microsoft Graph
End-to-End User Offboarding with Microsoft Graph PowerShell
Leavers retaining residual access is a chronic security risk. This walkthrough turns one HR row into a fully offboarded user with sessions revoked, mailbox converted to shared, OneDrive transferred to the manager, groups cleared, and licences released, all with a clean audit trail.
Automating Intune Win32 App Packaging with GitHub Actions
Intune’s Win32 app channel is powerful, but its packaging workflow is stuck in 2018. Here is a GitHub Actions pipeline that builds .intunewin packages, uploads them to Intune through Microsoft Graph using federated credentials, and keeps every app’s metadata version controlled in Git.
Cleaning Up Stale Entra ID Devices with Microsoft Graph PowerShell
Stale device records bloat Conditional Access scope and skew Intune compliance numbers. This walkthrough shows how to find, classify, disable, and eventually delete inactive Entra ID devices with Microsoft Graph PowerShell, with full audit safety.
Conditional Access Policy Backups via PowerShell
Conditional Access policies are critical Entra ID security controls, but many tenants have no backup or version history. This walkthrough builds a short PowerShell script that exports every CA policy to JSON and commits it to Git, giving you an auditable, restorable baseline you can schedule in Azure Automation or GitHub Actions.
Automate App Registration Secret Expiry Alerts
Expired application secrets are one of the most common causes of silent production outages in Microsoft 365 environments. An app registration in Entra ID powers everything from automated workflows and API integrations to third-party SaaS connectors. When its client...
Automate Entra Guest User Lifecycle with PowerShell
Learn how to automate the full Entra ID guest user lifecycle using PowerShell and the Microsoft Graph API. This guide covers discovery, stale account detection, notification emails, and safe two-phase removal to keep your Microsoft 365 tenant clean and compliant.
Automating MFA Audits in Entra ID with PowerShell
Learn how to audit MFA registration status across your entire Microsoft Entra ID tenant using PowerShell and the Microsoft Graph API. Includes filtering, CSV export, and a fully automated scheduled reporting script.
App-Only Auth for Microsoft Graph with PowerShell
A step-by-step guide to creating an Entra ID app registration, generating a self-signed certificate, assigning Microsoft Graph API permissions, and connecting with PowerShell for fully unattended automation.
Migrating from AzureAD PowerShell to Microsoft Entra PowerShell
AzureAD and MSOnline PowerShell modules have been retired by Microsoft. If your scripts still rely on them, they are broken or will be soon. This guide shows you how to migrate…

