Public/Get-GraphConnectionCommand.ps1

function Get-GraphConnectionCommand {
    <#
    .SYNOPSIS
        Returns a delegated Connect-MgGraph command for each least-privilege scope and operation.
    .DESCRIPTION
        Permission alternatives are returned separately, never combined into a broader scope set.
        Does not connect or execute the generated command. Application authentication does not use -Scopes.
    .EXAMPLE
        Get-GraphConnectionCommand -Cmdlet Get-MgUser -Endpoint /users
    #>

    [CmdletBinding()]
    [OutputType('GraphShell.ConnectionCommand')]
    param(
        [Parameter(Mandatory, ValueFromPipeline)][string]$Cmdlet,
        [ValidateSet('DelegatedWork','DelegatedPersonal')][string]$PermissionType = 'DelegatedWork',
        [string]$Endpoint,
        [ValidateSet('v1.0','beta')][string]$ApiVersion = 'v1.0'
    )
    process {
        $mappings = @(Get-GraphMapping -Cmdlet $Cmdlet -IncludeDetails | Where-Object {
            $_.ApiVersion -eq $ApiVersion -and (-not $Endpoint -or $_.Endpoint -eq $Endpoint)
        })
        $found = $false
        foreach ($mapping in $mappings) {
            foreach ($permission in @($mapping.Permissions | Where-Object {
                $_.IsLeastPrivilege -eq $true -and $_.PermissionType -eq $PermissionType
            } | Sort-Object Name -Unique)) {
                $found = $true
                [pscustomobject]@{
                    PSTypeName = 'GraphShell.ConnectionCommand'
                    Cmdlet = $mapping.Cmdlet
                    Endpoint = $mapping.Endpoint
                    Method = $mapping.Method
                    ApiVersion = $mapping.ApiVersion
                    PermissionType = $PermissionType
                    Scope = $permission.Name
                    Command = "Connect-MgGraph -Scopes '$($permission.Name.Replace("'", "''"))'"
                }
            }
        }
        if (-not $found) { Write-Warning "No least-privilege delegated scope is recorded for '$Cmdlet' and the selected operation." }
    }
}