Automating User Offboarding in Azure AD with PowerShell
One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Thread: The Microsoft Graph toolbox ↗Tagged · 12 notes
Everything tagged Entra ID, wherever it's filed, newest first.
One script that locks a departing user out, cleans up their groups and licenses, and keeps their mail, with a CSV record of every step.
Thread: The Microsoft Graph toolbox ↗Put a domain group into the local Administrators group on a list of computers (or take one out) over PowerShell remoting, with a result for every machine and -WhatIf first.
Thread: Local admin, done right ↗Before you rename, rescope or delete a group, find out what it's wired to. Members, owners, licenses, apps and Intune policies, in one report.
Thread: The Microsoft Graph toolbox ↗Roll out a named local admin account with a random password nobody knows, ready for Windows LAPS to take over, and optionally retire the built-in Administrator.
Thread: Local admin, done right ↗For the Entra-joined PC that never showed up in Intune. Check it's ready, kick off enrollment, and see why it failed if it does.
Thread: Getting devices into Intune ↗Load mobile numbers into Entra ID as an authentication method before users ever sign in, without stomping on numbers they've already registered.
Thread: The Microsoft Graph toolbox ↗A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗The Settings app route into Intune, which of its three options to pick, and why the device might show up as personal when you didn't want it to.
Thread: Getting devices into Intune ↗A practical checklist for taking a device that gets its security policy through Defender for Endpoint and enrolling it in Intune without leaving a gap.
Thread: Getting devices into Intune ↗Write extensionAttribute1-15 on cloud-only Entra ID users from a CSV, with a clear note for every synced account it can't touch.
Thread: The Microsoft Graph toolbox ↗Onboarding to Defender for Endpoint and enrolling in Intune are two different things, and you almost never have to offboard one to get the other.
Thread: Getting devices into Intune ↗Force an immediate local admin password rotation on every machine in a collection, with Windows LAPS doing the password part so no script ever sees one.
Thread: Local admin, done right ↗