SPClean

2.2.0

Keep your SharePoint Online environment clean, secure, and compliant. SPClean helps Microsoft 365 administrators quickly discover orphaned users, stale identities, and disconnected guest accounts that can create security and governance risks. With automated detection, detailed reporting, and remediation capabilities, SPClean turns hours of manual investigation into a
Keep your SharePoint Online environment clean, secure, and compliant. SPClean helps Microsoft 365 administrators quickly discover orphaned users, stale identities, and disconnected guest accounts that can create security and governance risks. With automated detection, detailed reporting, and remediation capabilities, SPClean turns hours of manual investigation into a repeatable and scalable process. Supports App-Only authentication, scheduled execution, permission snapshots, and HTML/CSV/JSON reporting.
Show more

Minimum PowerShell version

7.0

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name SPClean

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name SPClean

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) 2026 David Pham. Licensed under the MIT License.

Package Details

Author(s)

  • David Pham

Tags

SharePoint SPO SharePointOnline Orphaned Cleanup M365 MicrosoftGraph PnP Governance Remediation EntraID Storage Optimization

Functions

Connect-SPCTenant Disconnect-SPCTenant Get-SPCOrphanedUser Get-SPCMismatchUser Export-SPCReport Remove-SPCOrphanedUser Restore-SPCOrphanedUser Repair-SPCMismatchUser New-SPCScanSchedule Register-SPCLicense Get-SPCLicenseInfo Get-SPCGuestAccess Get-SPCPrivilegedUser Get-SPCOverPermissionedUser Get-SPCPermissionHealthScore Get-SPCBrokenInheritance Compare-SPCPermissionSnapshot Invoke-SPCDashboardReport Invoke-SPCPermissionAnalytics Get-SPCStorageWaste Get-SPCInactiveSite Get-SPCVersionWaste Get-SPCPreservationHoldWaste Clear-SPCRecycleBin Optimize-SPCFileVersion Export-SPCStorageReport

Dependencies

Release Notes

## 2.1.1 - 2026-08-16
- Fix: Resolved JavaScript SyntaxError in `Export-SPCStorageReport` / `New-SPCStorageDashboardHtmlInternal` where ES6 template literals inside PowerShell here-strings caused empty Top Storage Waste Sites tables.

## 2.1.0 - 2026-08-16
- Fixed: Resolved site URLs via PnP SiteId when M365 privacy concealment is enabled in Microsoft 365 Admin Center reports.
- Fixed: Enhanced interactive token resolution to acquire dedicated SharePoint resource tokens for individual site connections and filter out redirect sites.
- Fixed: Properly hydrate CSOM Site.Usage properties via Get-PnPProperty to retrieve exact storage metrics in PnP PowerShell 3.2+.
- Fixed: Resilient scanning when auditing storage waste on preservation hold sites.
- Security & Compliance: Non-destructive Microsoft Purview Preservation Hold Library (PHL) immunity protection.
- Architecture: Centralized PnP wrapper layer in `Private/PnPWrappers.ps1` with PnP 3.2.0 compatibility and zero unmanaged memory residue (`ZeroFreeBSTR`).
- Performance: Exponential backoff with jitter retry on Microsoft Graph 429 throttling and automatic fallback to SharePoint Online Admin API.

## 1.6.0 - 2026-08-14
- Security: Connect-SPCTenant pipeline output sanitized to remove raw GraphAccessToken; provides IsGraphConnected and TokenExpiresAt.
- Security: Get-SPCOrphanedUser escapes single quotes and URI encodes UPNs in Graph OData queries.
- Refactor: Standardized cmdlet names Invoke-SPCDashboardReport and Invoke-SPCPermissionAnalytics with backward-compatible aliases.
- Refactor: Centralized per-site connection logic into Private/Connect-SPCSiteInternal.ps1.
- Refactor: Renamed scoring engine to Measure-SPCScoreInternal adhering to PowerShell approved verbs.
- Refactor: Separated skippedCount from errorCount in Remove-SPCOrphanedUser.
- Architecture: Snapshot schema bumped to v1.1 with isEmptyPermissionSet flag; Restore-SPCOrphanedUser supports both v1.0 and v1.1.

## 1.5.2 - 2026-08-01
- Feature: Permission Health Score calculation and broken inheritance analytics.

## 1.3.0 - 2026-07-17
- Feature: Added `Get-SPCMismatchUser` to detect User ID Mismatches between SharePoint UIL and Entra ID.
- Feature: Added `Repair-SPCMismatchUser` to automatically backup, clean, and restore Web and List level permissions for mismatched users.

## 1.2.3 - 2026-07-15
- Fix: Guest users are now correctly skipped during Mismatch Repair.

## 1.1.6 - 2026-06-27
- Fix: New-SPCScanSchedule scheduled task no longer opens a visible PowerShell window (-WindowStyle Hidden added)

## 1.1.5 - 2026-06-27
- Fix: New-SPCScanSchedule incorrectly detected Windows as non-Windows (Get-Variable $IsWindows unreliable inside module scope); replaced with [System.Environment]::OSVersion.Platform check

## 1.1.4 - 2026-06-27
- Fix: New-SPCScanSchedule -OutputPath alias added (parameter was named -ReportOutputPath, causing ParameterNotFound error)
- Docs: Restore-SPCOrphanedUser limitations - clarify soft-deleted accounts must be restored in Entra first

## 1.1.3 - 2026-06-27
- Fix: Export-SPCReport HTML footer shows correct version instead of System.Object[]

## 1.1.2 - 2026-06-27
- Fix: CI publish workflow now injects HMAC secret before packaging (license key validation works in published module)
- Fix: Interactive auth docs - add http://localhost redirect URI requirement (AADSTS50011)

## 1.1.1 - 2026-06-27
- Fix: exclude .git folder from PSGallery package

## 1.1.0 - 2026-06-26
- Register-SPCLicense: offline HMAC-SHA256 license key activation
- Get-SPCLicenseInfo: query current tier (FREE / PRO / CONSULTANT)
- Feature gates: HTML report, CreateSnapshot, Restore, Schedule require Pro/Consultant
- MkDocs Material documentation site (https://hungpham2802.github.io/SPClean)

## 1.0.0 - 2026-06-22
- Connect-SPCTenant: Interactive and AppOnly (certificate/secret) auth
- Get-SPCOrphanedUser: detects Deleted, SoftDeleted, Disabled, GuestOrphaned accounts
- Export-SPCReport: CSV, HTML (colour-coded risk badges), JSON output
- Remove-SPCOrphanedUser: removes users with WhatIf/Confirm/CreateSnapshot support
- Restore-SPCOrphanedUser: re-applies permissions from JSON snapshot
- New-SPCScanSchedule: Windows Scheduled Task automation

FileList

Version History

Version Downloads Last updated
2.2.0 (current version) 5 8/18/2026
2.1.1 4 8/16/2026
2.1.0 5 8/16/2026
2.0.0 5 8/15/2026
1.5.2 5 8/13/2026
1.5.1 8 8/8/2026
1.3.1 11 7/29/2026
1.3.0 15 7/17/2026
1.2.3 8 7/17/2026
1.2.2 11 7/11/2026
1.1.6 18 6/27/2026
Show more