In this video we will explore how to collect permissions assigned across RBAC, Entra roles, and Microsoft Graph, and then upload everything into a Excel worksheet.
------------------------- C H A P T E R S -------------------------
00:00 Intro
01:11 Setup AuthN
02:04 Collect Data From RBAC (MG, Sub, RG)
15:08 Collect Data from Entra Roles (EntraID, M365, Etc)
21:08 Collect Data From Graph (App Roles & User Scopes)
32:37 Collect GroupMembers for Group Reference
35:45 Upload Data to Excel In SharePoint
40:03 See the Data being added to Excel!
40:51 Outro
------------------------- O V E R V I E W -------------------------
In this video we will explore how to collect permissions assigned across RBAC, Entra roles, and Microsoft Graph, and then upload everything into a Excel worksheet.
🔹 With RBAC, we will collect role assignments at the Management Group, Subscription, and Resource Group levels
🔹 We will skip individual resources, but once you see the pattern, extending it is very simple (especially if you want to see access in priv resources like key vaults)
🔹 I will also show how to narrow this down to only privileged roles if that is all you care about
🔹 Next, we will explore Entra roles like Global Administrator, Helpdesk Administrator, Global Reader, and more
🔹 These roles apply across Microsoft cloud services like Entra, M365, Defender, Purview, etc
🔹 If all you had was a PrincipalId and had no idea whether it was a user, group, or service principal, I will demo how to resolve it using just the ID
🔹 Then we will move into Microsoft Graph permissions
🔹 This includes permissions assigned to service principals and users who can run Graph APIs or cmdlets
🔹 We will collect exactly what permissions they have and include that in the report
🔹 Graph has three service principals you always need to be mindful of: Microsoft Graph, Graph Explorer, Microsoft Graph Command Line Tools
🔹 I will show how to retrieve permissions from all three.
🔹 Since some access is granted through groups, we will also collect group membership (completely optional)
🔹 This will be stored in a separate reference worksheet so you can easily see who effectively has access
🔹 Finally, we will take all the data we collected and build an Excel document directly in SharePoint
🔹 No local files, we will do it directly in SharePoint like we learnt from my recent video
🔹 Check out 40:00 to see the data being built live! Its pretty cool!
By the end of this video, you will have instant visibility across your tenant for Azure, Entra ID, Microsoft 365, Graph, etc. This makes it much easier to see who has what access, spot anomalies, support compliance work, or generate reports for your teams and managers.
Show your support:
🔔 Subscribe for more videos in the series: PowerShell Engineering
👍 Like this video.
Links:
⚙️GitHub: https://github.com/adeelautomates/Pow...
#azure #entraid #powershell
In this video we will explore how to collect permissions assigned across RBAC, Entra roles, and Microsoft Graph, and then upload everything into a Excel worksheet.
------------------------- C H A P T E R S -------------------------
00:00 Intro
01:11 Setup AuthN
02:04 Collect Data From RBAC (MG, Sub, RG)
15:08 Collect Data from Entra Roles (EntraID, M365, Etc)
21:08 Collect Data From Graph (App Roles & User Scopes)
32:37 Collect GroupMembers for Group Reference
35:45 Upload Data to Excel In SharePoint
40:03 See the Data being added to Excel!
40:51 Outro
------------------------- O V E R V I E W -------------------------
In this video we will explore how to collect permissions assigned across RBAC, Entra roles, and Microsoft Graph, and then upload everything into a Excel worksheet.
🔹 With RBAC, we will collect role assignments at the Management Group, Subscription, and Resource Group levels
🔹 We will skip individual resources, but once you see the pattern, extending it is very simple (especially if you want to see access in priv resources like key vaults)
🔹 I will also show how to narrow this down to only privileged roles if that is all you care about
🔹 Next, we will explore Entra roles like Global Administrator, Helpdesk Administrator, Global Reader, and more
🔹 These roles apply across Microsoft cloud services like Entra, M365, Defender, Purview, etc
🔹 If all you had was a PrincipalId and had no idea whether it was a user, group, or service principal, I will demo how to resolve it using just the ID
🔹 Then we will move into Microsoft Graph permissions
🔹 This includes permissions assigned to service principals and users who can run Graph APIs or cmdlets
🔹 We will collect exactly what permissions they have and include that in the report
🔹 Graph has three service principals you always need to be mindful of: Microsoft Graph, Graph Explorer, Microsoft Graph Command Line Tools
🔹 I will show how to retrieve permissions from all three.
🔹 Since some access is granted through groups, we will also collect group membership (completely optional)
🔹 This will be stored in a separate reference worksheet so you can easily see who effectively has access
🔹 Finally, we will take all the data we collected and build an Excel document directly in SharePoint
🔹 No local files, we will do it directly in SharePoint like we learnt from my recent video
🔹 Check out 40:00 to see the data being built live! Its pretty cool!
By the end of this video, you will have instant visibility across your tenant for Azure, Entra ID, Microsoft 365, Graph, etc. This makes it much easier to see who has what access, spot anomalies, support compliance work, or generate reports for your teams and managers.
Show your support:
🔔 Subscribe for more videos in the series: PowerShell Engineering
👍 Like this video.
Links:
⚙️GitHub: https://github.com/adeelautomates/Pow...
#azure #entraid #powershell
For that what you really should use is KQL in Azure Resource Graph. Where it would it takes milliseconds (if not a few seconds) to get every RBAC at every level (including resource level which I didn't include in the video). I didn't share KQL as at the time of recording this episode had not covered it. Since then I have made a video on KQL.
https://www.youtube.com/watch?v=3ehLkgsgyvg
In case you want to learn KQL and more importantly near the end see the KQL query that could generate this exact RBAC permissions in your powershell scripts.