AzureScout

3.7.0

AzureScout — discover, inventory, and assess everything in your Azure environment from one command. Run Invoke-AzureScout with no parameters for a guided wizard, or drive it with switches: by default it inventories Azure resources, Entra ID, and identity objects (Excel, JSON, Markdown, AsciiDoc); add -Assessment and it runs a read-only CAF/WAF landing-zone assessment,
AzureScout — discover, inventory, and assess everything in your Azure environment from one command. Run Invoke-AzureScout with no parameters for a guided wizard, or drive it with switches: by default it inventories Azure resources, Entra ID, and identity objects (Excel, JSON, Markdown, AsciiDoc); add -Assessment and it runs a read-only CAF/WAF landing-zone assessment, scoring the tenant against Cloud Adoption Framework design areas and Well-Architected pillars and producing Power BI, self-contained HTML, executive PowerPoint, and JSON/Excel evidence. See everything. Own your cloud. (Requires PowerShell 7 on PowerShell Core.)
Show more

Minimum PowerShell version

7.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name AzureScout -RequiredVersion 3.7.0

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name AzureScout -Version 3.7.0

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Hybrid Cloud Solutions. All rights reserved.

Package Details

Author(s)

  • Kristopher Turner

Tags

Azure AzureScout Discovery Inventory Assessment CAF WAF WellArchitected CloudAdoptionFramework LandingZone Governance AZSC EntraID Resources ARM Graph Reporting Excel PowerBI

Functions

Start-AZSCAdvisoryJob Start-AZSCPolicyJob Start-AZSCSecCenterJob Start-AZSCSubscriptionJob Wait-AZSCJob Build-AZSCDiagramSubnet Set-AZSCDiagramFile Start-AZSCDiagramJob Start-AZSCDiagramNetwork Start-AZSCDiagramOrganization Start-AZSCDiagramSubscription Start-AZSCDrawIODiagram Invoke-AzureScout Test-AZSCPermissions Start-AZSCWizard Test-ScoutPermission Invoke-ScoutPipeline Get-ScoutInventoryDrift Get-ScoutCostAnomaly Get-ScoutIacGap Import-ScoutConfig Export-ScoutConfig

PSEditions

Core

Dependencies

This module has no dependencies.

Release Notes

v3.7.0 - The network picture, completed. The assessment collect gains the networking relationship data the diagrams were starving for: vnetPeerings (remote VNet named, peering state, gateway-transit flags), vpnConnections (sharedKeyPresent as a bool only - the pre-shared key value is never collected), localNetworkGateways, virtualHubs, and richer expressRouteCircuits, routeTables (a forced-tunnel 0.0.0.0/0 route is detectable from a scalar), loadBalancers, applicationGateways (wafEnabled), frontDoors, trafficManagerProfiles, natGateways and bastionHosts - both collect paths produce identical shapes, gated by two new plumbing test suites. The VNet connectivity diagram draws real peering-pair edges; the hybrid diagram gains per-connection detail, an ExpressRoute lane and Virtual WAN hubs; two new diagrams land: Edge & delivery and Routing & forced tunnelling. The wizard's 46-entry assessment menu is grouped under CAF / WAF / Specialized reviews / Service category deep-dives without renaming a single registry key. v3.6.1 - Four field defects from one live session, every one reported by the owner running the shipped module. (1) The Graph token now targets the tenant being audited instead of az CLI's ambient default: on a multi-tenant identity the Entra ID P2 licence check read a different tenant's subscribedSkus and reported a licensed tenant as NOT LICENSED; -TenantID is threaded through the token helper (per-tenant token cache), the Graph request wrapper, and every Graph call in the permission audit. (2) A combined Inventory+Assessment run writes ONE output folder: the deferred assessment's OutputPath was captured before the timestamped run folder existed, so the React report - the only renderer that path produces - landed in a sibling folder the operator was never told about. (3) The permission audit now decodes its own token's scp claim: scopes Azure CLI can never acquire (Policy.Read.AuthenticationMethod, VerifiedId-Profile.Read.All) are reported as UNAVAILABLE WITH CLI SIGN-IN with service-principal remediation instead of DENIED advice that fails a Global Administrator identically - proven live by decoding a real az token and reproducing the 403. (4) The four approved network diagrams - VNet hub-and-spoke with no-peering warnings, hybrid site-to-site with a single-instance gateway warning, private link and DNS, internet exposure - are ported from the approved mockup into the shipping React report's diagram kernel with sidebar, tiles, panes and overlap-gate coverage; the port caught a wrong node CSS class that hid the diagrams from the collision gate and a gate shape mismatch that made it inspect nothing. v3.6.0 - The collector-payload wiring audit, closed out. Nearly 100 collector manifests existed, were fully tested, and produced Excel-only rows - but never reached the assessment collect (collect.json) the React report actually renders from. This release closes that gap: 95 collectors wired across Networking, Hybrid, Monitor, Defender, Databases, DevOps, Management, Security, Storage, and Update Manager categories (coverage moves from 77 to 172 of 245 tracked manifests), plus 3 genuinely new collectors authored from scratch for services that had none - Microsoft Entra Verified ID and Microsoft Entra External ID (the governance/landing-zone-relevant one), both Graph-backed rather than ARM/ARG. Along the way, a real defect in the test suite's own infrastructure was found and fixed: a shared mock-cleanup idiom silently no-opped, letting mock state leak across test files - corrected everywhere it appeared, restoring a genuinely clean full test run. See CHANGELOG.md for the full history.

FileList

Version History

Version Downloads Last updated
3.12.3 8 8/12/2026
3.12.2 8 8/12/2026
3.12.1 8 8/11/2026
3.12.0 8 8/11/2026
3.11.0 6 8/11/2026
3.10.2 7 8/10/2026
3.10.1 7 8/10/2026
3.10.0 7 8/10/2026
3.9.0 6 8/9/2026
3.8.4 6 8/9/2026
3.8.3 6 8/9/2026
3.8.2 5 8/9/2026
3.8.1 7 8/9/2026
3.8.0 6 8/8/2026
3.7.0 (current version) 7 8/8/2026
3.6.1 6 8/8/2026
3.6.0 8 8/8/2026
3.5.1 11 8/4/2026
3.5.0 7 8/4/2026
3.3.4 7 8/4/2026
3.3.3 8 8/3/2026
3.3.2 5 8/3/2026
3.3.1 7 8/3/2026
3.3.0 6 8/3/2026
3.1.0 10 7/31/2026
3.0.9 8 7/31/2026
3.0.8 5 7/30/2026
3.0.7 4 7/30/2026
3.0.6 8 7/30/2026
3.0.5 9 7/29/2026
3.0.4 5 7/29/2026
3.0.3 4 7/29/2026
3.0.2 8 7/29/2026
3.0.1 5 7/29/2026
3.0.0 10 7/28/2026
2.11.0 10 7/26/2026
2.10.0 6 7/26/2026
2.9.0 10 7/26/2026
2.8.0 6 7/26/2026
2.7.0 8 7/26/2026
2.6.0 6 7/26/2026
2.5.3 5 7/25/2026
2.5.2 9 7/25/2026
2.5.1 5 7/25/2026
2.5.0 6 7/25/2026
2.4.0 5 7/25/2026
2.3.0 7 7/25/2026
2.2.0 5 7/24/2026
2.1.0 6 7/24/2026
2.0.1 7 7/23/2026
2.0.0 5 7/23/2026
1.0.0 48 2/25/2026
Show less