ServerBridge.LicenseScan

1.3.0

Free, read-only Microsoft 365 admin scans. Invoke-LicenseScan cross-checks every assigned license against real sign-in or usage activity and shows the seats you pay for that nobody uses, in dollars. Invoke-OffboardingCheck finds accounts that look like leavers and shows what they still hold: licenses, group memberships, and mailboxes never converted to shared. Device-
Free, read-only Microsoft 365 admin scans. Invoke-LicenseScan cross-checks every assigned license against real sign-in or usage activity and shows the seats you pay for that nobody uses, in dollars. Invoke-OffboardingCheck finds accounts that look like leavers and shows what they still hold: licenses, group memberships, and mailboxes never converted to shared. Device-code sign-in, no app registration, nothing stored, never changes your tenant.
Show more

Minimum PowerShell version

5.1

Installation Options

Copy and Paste the following command to install this package using PowerShellGet More Info

Install-Module -Name ServerBridge.LicenseScan

Copy and Paste the following command to install this package using Microsoft.PowerShell.PSResourceGet More Info

Install-PSResource -Name ServerBridge.LicenseScan

You can deploy this package directly to Azure Automation. Note that deploying packages with dependencies will deploy all the dependencies to Azure Automation. Learn More

Manually download the .nupkg file to your system's default download location. Note that the file won't be unpacked, and won't include any dependencies. Learn More

Owners

Copyright

(c) Lee Crowe Software Solutions LLC. MIT License.

Package Details

Author(s)

  • Lee Crowe Software Solutions LLC

Tags

Microsoft365 M365 Office365 Licensing License Audit CostOptimization Offboarding StaleAccounts Mailbox MicrosoftGraph Entra ReadOnly Windows Linux MacOS

Functions

Invoke-LicenseScan Invoke-OffboardingCheck

PSEditions

Desktop Core

Dependencies

Release Notes

Changed: failed sign-in attempts no longer make a dormant account look active. lastSignInDateTime records attempts including failures, so an account being password-sprayed kept a fresh timestamp and stayed licensed without review. Both commands now read the newest of the non-interactive and successful timestamps, with a fallback if lastSuccessfulSignInDateTime is empty across a whole tenant. Affects Entra ID P1/P2 tenants only. Raised by iRyan23 on r/entra. New (experimental): Invoke-OffboardingCheck -UseExchangeOnline reads mailbox types from Exchange Online, which unlike Microsoft's usage report can see mailboxes that have never been used. Off by default; needs a second sign-in. Fixed: signing in with a personal Microsoft account now says to use your work account instead of suggesting you check permissions. See CHANGELOG.md on GitHub.

FileList

Version History

Version Downloads Last updated
1.3.0 (current version) 7 9/23/2026
1.2.2 6 9/22/2026
1.2.1 9 9/17/2026
1.2.0 9 9/16/2026
1.1.1 5 9/15/2026
1.1.0 6 9/14/2026
Show more