Public/Get-IntuneChangePreview.ps1

function Get-IntuneChangePreview {
    <#
    .SYNOPSIS
    Shows what depends on an Entra group, assignment filter or scope tag before you change or delete it.
    .DESCRIPTION
    Lists the policies, apps, scripts, updates and Intune role assignments that reference the object,
    and flags risks such as unreadable (possibly deleted) groups, groups used for both inclusion and
    exclusion, groups that control both administration and targeting, and scope tags no role
    assignment grants. Uses collected evidence only. Read only.
    .PARAMETER Name
    Group, filter or scope tag display name. Wildcards are supported.
    .PARAMETER Id
    Exact object ID.
    .PARAMETER SubjectType
    Limit results to Group, AssignmentFilter or ScopeTag.
    .PARAMETER SnapshotPath
    Use a local IntuneAccess snapshot instead of a live collection.
    .PARAMETER FlaggedOnly
    Return only objects with at least one risk flag.
    .EXAMPLE
    Get-IntuneChangePreview -Name 'All Corporate Laptops'
    .EXAMPLE
    Get-IntuneChangePreview -FlaggedOnly
    #>

    [CmdletBinding()]
    param(
        [ValidateNotNullOrEmpty()] [string] $Name = '*',
        [ValidateNotNullOrEmpty()] [string] $Id,
        [ValidateSet('Group', 'AssignmentFilter', 'ScopeTag')] [string[]] $SubjectType = @('Group', 'AssignmentFilter', 'ScopeTag'),
        [ValidateNotNullOrEmpty()] [string] $SnapshotPath,
        [switch] $FlaggedOnly
    )

    $collection = Get-IntuneAccessInsightCollection -SnapshotPath $SnapshotPath -IncludeWorkloadAssignments
    foreach ($subject in @(Get-IntuneAccessDependencyIndex -Collection $collection)) {
        if ($subject.SubjectType -notin $SubjectType) { continue }
        if ($PSBoundParameters.ContainsKey('Id') -and $subject.Id -ne $Id) { continue }
        if ($subject.Name -notlike $Name) { continue }
        if ($FlaggedOnly -and @($subject.Flags).Count -eq 0) { continue }
        $subject
    }
}