Invoke-M365TenantAudit

1.0.3

Connects to Microsoft Graph with read-only permissions, checks common
Microsoft 365 / Entra ID security baseline items and writes a
self-contained HTML report.

THIS SCRIPT MAKES NO CHANGES TO YOUR TENANT.

Checks:
 - Licensing (Entra ID P1/P2 detection)
 - Security Defaults / Conditional Access (MFA for all, legacy auth block,
   admin MFA, break-glass exclusions,
Connects to Microsoft Graph with read-only permissions, checks common
Microsoft 365 / Entra ID security baseline items and writes a
self-contained HTML report.

THIS SCRIPT MAKES NO CHANGES TO YOUR TENANT.

Checks:
 - Licensing (Entra ID P1/P2 detection)
 - Security Defaults / Conditional Access (MFA for all, legacy auth block,
   admin MFA, break-glass exclusions, report-only policies)
 - Global Administrator count
 - MFA registration (all users + admins)
 - Stale / never-used accounts and guests
 - User consent to apps, guest invite settings, app creation
 - App registration secrets/certificates (expired / expiring)
 - Microsoft Secure Score
 - Intune compliance policies
 - Email DNS: SPF, DMARC, DKIM for each custom domain
 - Password expiration policy

Show more

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Script -Name Invoke-M365TenantAudit

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 Admin of One. MIT License.

Package Details

Author(s)

  • Admin of One

Tags

M365 Microsoft365 Security Audit EntraID ConditionalAccess Intune MFA

Functions

Add-Result Get-GraphObject Get-GraphCollection Get-ShortError Resolve-DohRecord Test-RequiresMfa Test-PhishingResistantStrength Get-GroupMemberIds Get-AdminCoverage ConvertTo-Html-Safe

Dependencies

This script has no dependencies.

Release Notes

1.0.3 - Admin MFA check now honours CA exclusions (excluded roles, users and groups) and only passes 'strong MFA' for a phishing-resistant authentication strength. The script no longer installs modules on its own; it tells you what to install and exits.
1.0.2 - Report footer links to the Tenant Lockdown Kit.
1.0.1 - Real-tenant fixes.

FileList

Version History

Version Downloads Last updated
1.0.3 (current version) 12 9/29/2026
1.0.2 8 9/29/2026