A tool for knowing where to manage identity objects in hybrid Microsoft environments.
In environments utilizing On-Premises Active Directory synced to Entra ID (Azure AD) alongside a Hybrid Exchange deployment, technicians often waste time checking multiple portals to figure out where an object's source of authority lies. hybrID takes an identity (UPN, sAMAccountName, or GUID), queries both On-Prem AD and the Microsoft Graph API, and indicates where to manage the identity its mail functionality, if any.
- Single Pane of Glass: Query an identity once to see its status across Active Directory, Entra ID, and Exchange Server/Online.
- Inbuilt Rules: Automatically determines if a mailbox is On-Premises, Exchange Online (EXO), or an EXO mailbox managed via On-Premises Remote Mailbox rules.
- Deep Linking: Generates dynamic, clickable URLs that drop the technician directly into the exact user or group profile blade in the Entra ID or Exchange Admin Centers.
- Modern UI: Built on WPF featuring a dark theme, hover tooltips, and a dynamic status bar.
- Frictionless Authentication: Silently caches Microsoft Graph API tokens to prevent repetitive login prompts.
To view the roadmap/potential future features, check out the roadmap!
To run this application, the technician's workstation must have the following installed:
- Windows PowerShell 5.1 (Standard on Windows 10/11).
- RSAT: Active Directory Domain Services and Lightweight Directory Services Tools (Provides the ActiveDirectory PowerShell module).
- Microsoft Graph PowerShell SDK (Specifically the Authentication, Users, and Groups sub-modules).
- Clone or download the repository to your local machine.
- Launch Windows PowerShell.
- Set your present working directory to the module root directory.
- Execute
hybrID.ps1from your terminal. - On first launch, you may be prompted to authenticate with Microsoft Graph. Sign in with your administrative credentials.
- Enter a sAMAccountName, UserPrincipalName, or ObjectGUID into the search bar and click Locate.
For more information, visit the docs.
For more screenshots, see screenshots.
This application is built using a modular PowerShell structure, separating the presentation layer (XAML) from the logic layer (private functions) and the execution layer. There is a public controller script to invoke the application.
hybrID/
├── assets/ # GitHub repository assets (readmes, badges)
├── build/ # Build scripts (e.g., PS2EXE wrappers)
├── docs/ # Project documentation
├── hybrID/ # Core Application Directory
│ ├── assets/ # Static app resources (icons, images)
│ ├── config/ # Application state (config.json)
│ ├── private/ # Internal PowerShell logic & helper functions
│ ├── public/ # Main controller script (hybrID.ps1)
│ └── ui/ # XAML presentation layer files
├── tests/ # Pester tests
├── .gitignore
└── README.md
Input: The app accepts an identity string.
On-Premises Check: Uses Get-ADObject to search Active Directory. It evaluates targetAddress, msExchHomeServerName, and mail attributes to determine Exchange routing.
Cloud Check: Uses Get-MgUser and Get-MgGroup to search Entra ID.
Evaluation:
- If found only in AD: Flags as On-Premises only.
- If found only in Graph: Flags as Cloud-only.
- If found in both: Flags as Hybrid/Synced and provides appropriate management paths based on your organization's specific sync rules.

