Public/Get-IntunePrivilegeUsage.ps1

function Get-IntunePrivilegeUsage {
    <#
    .SYNOPSIS
    Compares administrators' Intune write permissions with the changes they actually made.
    .DESCRIPTION
    For each administrator and permission family (for example Device Configurations or Mobile Apps),
    shows whether the Intune audit log contains changes they made in the collected window. Families with
    no audited activity are review prompts for least privilege. Read permissions are never reported as
    unused because Intune does not audit reads. Families without a direct audit mapping stay NotEvaluated.
    .PARAMETER UserPrincipalName
    Limit results to one administrator.
    .PARAMETER SnapshotPath
    Use a local IntuneAccess snapshot instead of a live collection.
    .EXAMPLE
    (Get-IntunePrivilegeUsage).Rows | Where-Object State -EQ 'NoObservedActivity'
    #>

    [CmdletBinding()]
    param(
        [ValidateNotNullOrEmpty()] [string] $UserPrincipalName,
        [ValidateNotNullOrEmpty()] [string] $SnapshotPath
    )

    $collection = Get-IntuneAccessInsightCollection -SnapshotPath $SnapshotPath -IncludeAuditEvidence
    $review = Get-IntuneAccessPrivilegeUsage -Collection $collection
    if ($PSBoundParameters.ContainsKey('UserPrincipalName')) {
        $review.Rows = @($review.Rows | Where-Object UserPrincipalName -EQ $UserPrincipalName)
        $review.NoObservedActivity = @($review.Rows | Where-Object State -EQ 'NoObservedActivity').Count
    }
    $review
}