threat-intel
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Medium
Summary
This article details a PowerShell script leveraging the Microsoft Graph API to extract detailed information about Microsoft 365 users, including their last password change date, login activity, and assigned licenses. The script allows for efficient identification of inactive accounts and unused licenses, potentially aiding in security audits and license management. The author highlights the ability to identify accounts for potential disabling or deletion, and suggests using the output for license management.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data