Export Microsoft 365 Group Report with MS Graph

Export Microsoft 365 Group Report with MS Graph
This commit is contained in:
AdminDroid 2023-04-25 13:10:33 +05:30
parent dbff9a3c80
commit 7b24f469c2

View File

@ -18,17 +18,36 @@ Param
[switch]$MailEnabledSecurity, [switch]$MailEnabledSecurity,
[Switch]$IsEmpty, [Switch]$IsEmpty,
[Int]$MinGroupMembersCount, [Int]$MinGroupMembersCount,
[string]$UserName, [string]$TenantId,
[string]$Password [string]$ClientId,
[string]$CertificateThumbprint
) )
Function Get_members Function Get_members
{ {
$DisplayName=$_.DisplayName $DisplayName=$_.DisplayName
Write-Progress -Activity "`n Processed Group count: $Count "`n" Getting members of: $DisplayName" Write-Progress -Activity "`n Processed Group count: $Count "`n" Getting members of: $DisplayName"
$EmailAddress=$_.EmailAddress $EmailAddress=$_.Mail
$GroupType=$_.GroupType if($_.GroupTypes -eq "Unified")
$ObjectId=$_.ObjectId {
$GroupType="Microsoft 365"
}
elseif($_.Mail -ne $null)
{
if($_.SecurityEnabled -eq $false)
{
$GroupType="DistributionList"
}
else
{
$GroupType="MailEnabledSecurity"
}
}
else
{
$GroupType="Security"
}
$GroupId=$_.Id
$Recipient="" $Recipient=""
$RecipientHash=@{} $RecipientHash=@{}
for($KeyIndex = 0; $KeyIndex -lt $RecipientTypeArray.Length; $KeyIndex += 2) for($KeyIndex = 0; $KeyIndex -lt $RecipientTypeArray.Length; $KeyIndex += 2)
@ -37,9 +56,9 @@ Function Get_members
$Value=$RecipientTypeArray[$KeyIndex+1] $Value=$RecipientTypeArray[$KeyIndex+1]
$RecipientHash.Add($key,$Value) $RecipientHash.Add($key,$Value)
} }
$Members=Get-MsolGroupMember -All -GroupObjectId $ObjectId $Members=Get-MgGroupMember -All -GroupId $GroupId
$MembersCount=$Members.Count $MembersCount=$Members.Count
$Members=$Members.AdditionalProperties
#Filter for security group #Filter for security group
if(($Security.IsPresent) -and ($GroupType -ne "Security")) if(($Security.IsPresent) -and ($GroupType -ne "Security"))
{ {
@ -71,26 +90,34 @@ Function Get_members
$RecipientTypeDetail="-" $RecipientTypeDetail="-"
Print_Output Print_Output
} }
#Loop through each member in a group #Loop through each member in a group
else else
{ {
foreach($Member in $Members) foreach($Member in $Members){
{
if($IsEmpty.IsPresent) if($IsEmpty.IsPresent)
{ {
return return
} }
$MemberName=$Member.DisplayName $MemberName=$Member.displayName
$MemberType=$Member.GroupMemberType if($Member.'@odata.type' -eq '#microsoft.graph.user')
$MemberEmail=$Member.EmailAddress {
$MemberType="User"
}
elseif($Member.'@odata.type' -eq '#microsoft.graph.group')
{
$MemberType="Group"
}
elseif($Member.'@odata.type' -eq '#microsoft.graph.orgContact')
{
$MemberType="Contact"
}
$MemberEmail=$Member.mail
if($MemberEmail -eq "") if($MemberEmail -eq "")
{ {
$MemberEmail="-" $MemberEmail="-"
} }
#Get Counts by RecipientTypeDetail #Get Counts by RecipientTypeDetail
foreach($key in [object[]]$Recipienthash.Keys) foreach($key in [object[]]$Recipienthash.Keys){
{
if(($MemberType -eq $key) -eq "true") if(($MemberType -eq $key) -eq "true")
{ {
[int]$RecipientHash[$key]+=1 [int]$RecipientHash[$key]+=1
@ -106,11 +133,15 @@ Function Get_members
if([int]$($_.Value) -gt 0 ) if([int]$($_.Value) -gt 0 )
{ {
if($Recipient -ne "") if($Recipient -ne "")
{ $Recipient+=";"} {
$Recipient+=";"
}
$Recipient+=@("$($_.Key) - $($_.Value)") $Recipient+=@("$($_.Key) - $($_.Value)")
} }
if($Recipient -eq "") if($Recipient -eq "")
{$Recipient="-"} {
$Recipient="-"
}
} }
#Print Summary report #Print Summary report
$Result=@{'DisplayName'=$DisplayName;'EmailAddress'=$EmailAddress;'GroupType'=$GroupType;'GroupMembersCount'=$MembersCount;'MembersCountByType'=$Recipient} $Result=@{'DisplayName'=$DisplayName;'EmailAddress'=$EmailAddress;'GroupType'=$GroupType;'GroupMembersCount'=$MembersCount;'MembersCountByType'=$Recipient}
@ -125,39 +156,54 @@ Function Print_Output
$Results= New-Object PSObject -Property $Result $Results= New-Object PSObject -Property $Result
$Results | Select-Object GroupName,GroupEmailAddress,Member,MemberEmail,MemberType | Export-Csv -Path $ExportCSV -Notype -Append $Results | Select-Object GroupName,GroupEmailAddress,Member,MemberEmail,MemberType | Export-Csv -Path $ExportCSV -Notype -Append
} }
Function CloseConnection
{
Disconnect-MgGraph | Out-Null
Exit
}
Function main() Function main()
{ {
#Check for MSOnline module #Check for MSOnline module
$Module=Get-Module -Name MSOnline -ListAvailable $MsGraphModule = Get-Module Microsoft.Graph -ListAvailable
if($Module.count -eq 0) if($MsGraphModule -eq $null)
{ {
Write-Host MSOnline module is not available -ForegroundColor yellow Write-host "Important: MicrosoftGraph module is unavailable. It is mandatory to have this module installed in the system to run the script successfully."
$Confirm= Read-Host Are you sure you want to install module? [Y] Yes [N] No $confirm= Read-Host Are you sure you want to install module? [Y] Yes [N] No
if($Confirm -match "[yY]") if($confirm -match "[yY]")
{ {
Install-Module MSOnline Write-host "Installing MicrosoftGraph module..."
Import-Module MSOnline Install-Module Microsoft.Graph -Repository PsGallery -Force -AllowClobber -Scope CurrentUser
Write-host "Required Module is installed in the machine Successfully" -ForegroundColor Magenta
} }
else else
{ {
Write-Host MSOnline module is required to connect AzureAD.Please install module using Install-Module MSOnline cmdlet. Write-host "Exiting. `nNote: MsGraph module must be available in your system to run the script. Please install required module." -ForegroundColor Red
Exit Exit
} }
} }
Write-Host Connecting to Office 365... Write-Host "Connecting to Microsoft Graph..."
$Scopes = @(
"Group.Read.All"
)
#Storing credential in script for scheduling purpose/ Passing credential as parameter #Storing credential in script for scheduling purpose/ Passing credential as parameter
if(($UserName -ne "") -and ($Password -ne "")) $Error.Clear()
if(($TenantId -ne "") -and ($ClientId -ne "") -and ($CertificateThumbprint -ne ""))
{ {
$SecuredPassword = ConvertTo-SecureString -AsPlainText $Password -Force try
$Credential = New-Object System.Management.Automation.PSCredential $UserName,$SecuredPassword {
Connect-MsolService -Credential $credential Connect-MgGraph -TenantId $TenantId -AppId $ClientId -CertificateThumbprint $CertificateThumbprint
}
catch
{
Write-Host "Please provide Correct Details!" -ForegroundColor Red
Exit
}
} }
else else
{ {
Connect-MsolService | Out-Null Connect-MgGraph -Scopes $Scopes
} }
Write-Host "Microsoft graph connected" -ForegroundColor Green
#Set output file #Set output file
$ExportCSV=".\M365Group-DetailedMembersReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm` tt).ToString()).csv" #Detailed report $ExportCSV=".\M365Group-DetailedMembersReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm` tt).ToString()).csv" #Detailed report
$ExportSummaryCSV=".\M365Group-SummaryReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm` tt).ToString()).csv" #Summary report $ExportSummaryCSV=".\M365Group-SummaryReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm` tt).ToString()).csv" #Summary report
@ -167,48 +213,54 @@ Function main()
$Result="" $Result=""
$Results=@() $Results=@()
$Count=0 $Count=0
Write-Progress -Activity "Collecting group info"
#Check for input file #Check for input file
if([string]$GroupIDsFile -ne "") if([string]$GroupIDsFile -ne "")
{ {
#We have an input file, read it into memory #We have an input file, read it into memory
$DG=@() $DG=@()
$DG=Import-Csv -Header "DisplayName" $GroupIDsFile $DG=Import-Csv -Header "DisplayName" $GroupIDsFile
foreach($item in $DG) foreach($item in $DG){
{ Get-MgGroup -GroupId $item.displayname | Foreach{
Get-MsolGroup -ObjectId $item.displayname | Foreach{
$Count++ $Count++
Get_Members} Get_Members
}
} }
} }
else else
{ {
#Get all Office 365 group #Get all Office 365 group
Get-MsolGroup -All | Foreach{ Get-MgGroup -All -ErrorAction SilentlyContinue -ErrorVariable PermissionError| Foreach{
$Count++ $Count++
Get_Members Get_Members
} }
if($PermissionError)
{
Write-Host "Please Add permissions!" -ForegroundColor Red
CloseConnection
}
} }
#Open output file after execution #Open output file after execution
Write-Host `nScript executed successfully Write-Host "Script executed successfully" -ForegroundColor Green
if((Test-Path -Path $ExportCSV) -eq "True") if((Test-Path -Path $ExportCSV) -eq "True")
{ {
Write-Host Detailed report available in: $ExportCSV Write-Host Detailed report available in: $ExportCSV -ForegroundColor Magenta
Write-host Summary report available in: $ExportSummaryCSV Write-host Summary report available in: $ExportSummaryCSV -ForegroundColor Magenta
$Prompt = New-Object -ComObject wscript.shell $Prompt = New-Object -ComObject wscript.shell
$UserInput = $Prompt.popup("Do you want to open output file?",` $UserInput = $Prompt.popup("Do you want to open output file?",` 0,"Open Output File",4)
0,"Open Output File",4)
If ($UserInput -eq 6) If ($UserInput -eq 6)
{ {
Invoke-Item "$ExportCSV" Invoke-Item "$ExportCSV"
Invoke-Item "$ExportSummaryCSV" Invoke-Item "$ExportSummaryCSV"
CloseConnection
} }
} }
Else Else
{ {
Write-Host No Group found. Write-Host "No group found" -ForegroundColor Red
CloseConnection
} }
} }
. main . main