Get Guest User Report with MS Graph PowerShell

Get Guest User Report with MS Graph PowerShell
This commit is contained in:
AdminDroid 2023-04-25 13:00:34 +05:30
parent 8bd03d7444
commit dbff9a3c80

View File

@ -1,126 +1,115 @@
#Accept input parameter <#
=============================================================================================
Name: Export Office 365 Guest user and their membership report using MS Graph PowerShell
Version: 3.0
Website: o365reports.com
For detailed Script execution: https://o365reports.com/2020/11/12/export-office-365-guest-user-report-with-their-membership/
============================================================================================
#>
#Accept input parameter
Param Param
( (
[Parameter(Mandatory = $false)] [Parameter(Mandatory = $false)]
[int]$StaleGuests, [int]$StaleGuests,
[int]$RecentlyCreatedGuests, [int]$RecentlyCreatedGuests,
[string]$UserName, [string]$TenantId,
[string]$Password [string]$ClientId,
[string]$CertificateThumbprint
) )
#Check for AzureAD module $MsGraphModule = Get-Module Microsoft.Graph -ListAvailable
$Module=Get-Module -Name AzureAD -ListAvailable if($MsGraphModule -eq $null)
if($Module.count -eq 0)
{ {
Write-Host AzureAD module is not available -ForegroundColor yellow Write-host "Important: Microsoft graph module is unavailable. It is mandatory to have this module installed in the system to run the script successfully."
$Confirm= Read-Host Are you sure you want to install module? [Y] Yes [N] No $confirm = Read-Host Are you sure you want to install Microsoft graph module? [Y] Yes [N] No
if($Confirm -match "[yY]") if($confirm -match "[yY]")
{ {
Install-Module AzureAD Write-host "Installing Microsoft graph module..."
Import-Module AzureAD Install-Module Microsoft.Graph -Scope CurrentUser
} Write-host "Microsoft graph module is installed in the machine successfully" -ForegroundColor Magenta
else }
{ else
Write-Host AzureAD module is required to connect AzureAD.Please install module using Install-Module AzureAD cmdlet. {
Exit Write-host "Exiting. `nNote: Microsoft graph module must be available in your system to run the script" -ForegroundColor Red
} Exit
} }
}
Write-Host Connecting Azure AD... -ForegroundColor Yellow if(($TenantId -ne "") -and ($ClientId -ne "") -and ($CertificateThumbprint -ne ""))
#Storing credential in script for scheduling purpose/ Passing credential as parameter
if(($UserName -ne "") -and ($Password -ne ""))
{ {
$SecuredPassword = ConvertTo-SecureString -AsPlainText $Password -Force Connect-MgGraph -TenantId $TenantId -AppId $ClientId -CertificateThumbprint $CertificateThumbprint -ErrorAction SilentlyContinue -ErrorVariable ConnectionError|Out-Null
$Credential = New-Object System.Management.Automation.PSCredential $UserName,$SecuredPassword if($ConnectionError -ne $null)
Connect-AzureAD -Credential $credential | Out-Null {
} Write-Host $ConnectionError -Foregroundcolor Red
else Exit
{ }
Connect-AzureAD | Out-Null }
} else
{
Connect-MgGraph -Scopes "Directory.Read.All" -ErrorAction SilentlyContinue -Errorvariable ConnectionError |Out-Null
if($ConnectionError -ne $null)
{
Write-Host "$ConnectionError" -Foregroundcolor Red
Exit
}
}
Write-Host "Microsoft Graph Powershell module is connected successfully" -ForegroundColor Green
Select-MgProfile beta
$Result="" $Result=""
$Results=@()
$GuestCount=0 $GuestCount=0
$PrintedGuests=0 $PrintedGuests=0
#Output file declaration #Output file declaration
$ExportCSV=".\GuestUserReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm` tt).ToString()).csv" $ExportCSV=".\GuestUserReport_$((Get-Date -format yyyy-MMM-dd-ddd` hh-mm-ss` tt).ToString()).csv"
Write-Host `nExporting report... Write-Host `nExporting report...
#Getting guest users #Getting guest users
Get-AzureADUser -All $true -Filter "UserType eq 'Guest'" | foreach { Get-MgUser -All -Filter "UserType eq 'Guest'" -ExpandProperty MemberOf | foreach {
$DisplayName=$_.DisplayName $DisplayName = $_.DisplayName
$Upn=$_.UserPrincipalName $GuestCount++
$GuestCount++ Write-Progress -Activity "`n Processed mailbox count: $GuestCount "`n" Currently Processing: $DisplayName"
Write-Progress -Activity "`n Processed mailbox count: $GuestCount "`n" Currently Processing: $DisplayName" $AccountAge = (New-TimeSpan -Start $_.CreatedDateTime).Days
$GetCreationTime=$_.ExtensionProperty
$CreationTime=$GetCreationTime.createdDateTime
$AccountAge= (New-TimeSpan -Start $CreationTime).Days
#Check for stale guest users #Check for stale guest users
if(($StaleGuests -ne "") -and ([int]$AccountAge -lt $StaleGuests)) if(($StaleGuests -ne "") -and ([int]$AccountAge -lt $StaleGuests))
{ {
return return
} }
#Check for recently created guest users #Check for recently created guest users
if(($RecentlyCreatedGuests -ne "") -and ([int]$AccountAge -gt $RecentlyCreatedGuests)) if(($RecentlyCreatedGuests -ne "") -and ([int]$AccountAge -gt $RecentlyCreatedGuests))
{ {
return return
} }
$Company = $_.CompanyName
$ObjectId=$_.ObjectId if($Company -eq $null)
$Mail=$_.Mail {
$Company=$_.CompanyName $Company = "-"
if($Company -eq $null) }
{ $GroupMembership = @($_.MemberOf.AdditionalProperties.displayName) -join ','
$Company="-" if($GroupMembership -eq $null)
} {
$CreationType=$_.CreationType $GroupMembership = '-'
$InvitationAccepted=$_.UserState }
#Export result to CSV file
#Getting guest user's group membership $PrintedGuests++
$Groups=(Get-AzureADUserMembership -ObjectId $ObjectId).DisplayName $Result = [PSCustomObject] @{'DisplayName'=$DisplayName;'UserPrincipalName'=$_.UserPrincipalName;'Company'=$Company;'EmailAddress'=$_.Mail;'CreationTime'=$_.CreatedDateTime ;'AccountAge(days)'=$AccountAge;'CreationType'=$_.CreationType;'InvitationAccepted'=$_.ExternalUserState;'GroupMembership'=$GroupMembership}
#$Groups $Result | Export-Csv -Path $ExportCSV -Notype -Append
$GroupMembership=""
foreach($Group in $Groups)
{
#$Group
if($GroupMembership -ne "")
{
$GroupMembership=$GroupMembership+","
}
$GroupMembership=$GroupMembership+$Group
}
if($GroupMembership -eq "")
{
$GroupMembership="-"
}
#Export result to CSV file
$PrintedGuests++
$Result=@{'UserPrincipalName'=$upn;'DisplayName'=$DisplayName;'EmailAddress'=$Mail;'Company'=$Company;'CreationTime'=$CreationTime;'AccountAge(days)'=$AccountAge;'InvitationAccepted'=$InvitationAccepted;'CreationType'=$CreationType; 'GroupMembership'=$GroupMembership}
$Output= New-Object PSObject -Property $Result
$Output | Select-Object DisplayName,UserPrincipalName,Company,EmailAddress,CreationTime,AccountAge'(Days)',CreationType,InvitationAccepted,GroupMembership | Export-Csv -Path $ExportCSV -Notype -Append
} }
#Open output file after execution #Open output file after execution
Write-Host `nScript executed successfully Write-Host `nScript executed successfully
if((Test-Path -Path $ExportCSV) -eq "True") if((Test-Path -Path $ExportCSV) -eq "True")
{ {
Write-Host "Detailed report available in: $ExportCSV" -ForegroundColor Green Write-Host "Detailed report available in: $ExportCSV" -ForegroundColor Green
Write-Host `nThe Output file contains $PrintedGuests guest users. Write-Host `nThe Output file contains $PrintedGuests guest users.
$Prompt = New-Object -ComObject wscript.shell $Prompt = New-Object -ComObject wscript.shell
$UserInput = $Prompt.popup("Do you want to open output file?",` $UserInput = $Prompt.popup("Do you want to open output file?",` 0,"Open Output File",4)
0,"Open Output File",4) if ($UserInput -eq 6)
If ($UserInput -eq 6) {
{ Invoke-Item "$ExportCSV"
Invoke-Item "$ExportCSV" }
} }
} else
Else {
{ Write-Host "No guest user found" -ForegroundColor Red
Write-Host No guest user found }
} Disconnect-MgGraph|Out-Null