Small, practical tools for Microsoft 365 identity, security and tenant work.
Each one solves a specific problem I've run into in real environments — tenant merges, cross-tenant trust, access that outlived its reason. Nothing here is a platform. Each tool does one job, reads what it needs, and tells you what it found.
| Folder | Tool | What it's for |
|---|---|---|
cross-tenant/ |
Get-CrossTenantAccessReview.ps1 |
Review Entra Cross-Tenant Access Policy: guest and Teams shared-channel access, trusted external MFA and devices, cross-tenant sync, dead partner entries. |
cross-tenant/ |
Get-CrossTenantInventory.ps1 |
Find what breaks when EWS is disabled: Free/Busy, MailTips and calendar sharing that still run on Exchange organization relationships, address spaces and sharing policies, with the Microsoft 365 capability each one needs. |
More get added over time.
Read-only by default. Unless a tool says otherwise in its name and its README, it reads and reports. Cleanup is always your decision, made with the output in front of you.
Least privilege. Each tool lists the exact roles and scopes it needs, and asks for nothing more.
No tenant data in this repo. The .gitignore blocks CSV, JSON and HTML output. If you contribute, never include real tenant IDs, domains, user names or configuration — synthetic examples only.
Test before you trust. Run anything here against a test tenant, or with read-only credentials, before relying on it. Microsoft changes APIs and module behavior more often than anyone would like.
Most tools need PowerShell 7 plus some combination of:
ExchangeOnlineManagement3.xMicrosoft.Graph.*modules
Each tool's README lists exactly which.
- copilot-readiness-framework — a method for assessing content exposure before a Microsoft 365 Copilot rollout
Charlie Delmotte — hybrid cloud and security architect, Geneva.