azureblog.co.uk
← cd ~/learn
azureblog.co.uk · cheat sheet

Microsoft Graph PowerShell essentials

Connecting, finding the right cmdlet and permission, filtering and paging: the commands you'll use every day.

Fits on one A4 page. Checked 9 Oct 2026.

Install and connect

Install-Module Microsoft.Graph -Scope CurrentUser
Install-Module Microsoft.Graph.Beta -Scope CurrentUser  # beta cmdlets

Connect-MgGraph -Scopes "User.Read.All","Group.Read.All"
Get-MgContext            # who and which scopes
Disconnect-MgGraph

Unattended

# App registration with a certificate
Connect-MgGraph -ClientId $appId -TenantId $tenantId `
  -CertificateThumbprint $thumb

# Managed identity (Automation, Functions, VMs)
Connect-MgGraph -Identity

Guide: certificate authentication for scripts.

Find the cmdlet and permission

Find-MgGraphCommand -Command Get-MgUser | Select -First 1 -Expand Permissions
Find-MgGraphCommand -Uri "/users/{id}/memberOf"
Find-MgGraphPermission user -PermissionType Delegated

Moving from MSOnline or AzureAD? Use the cmdlet translator.

Filter, select, page

Get-MgUser -All -Filter "accountEnabled eq true" `
  -Property DisplayName,UserPrincipalName,SignInActivity

# Advanced queries need eventual consistency and a count
Get-MgUser -Filter "endsWith(mail,'@contoso.com')" `
  -ConsistencyLevel eventual -CountVariable n -All

Get-MgGroupMember -GroupId $gid -All

Gotchas

  • Missing properties? Most cmdlets return a default set. Ask for others with -Property, for example SignInActivity or OnPremisesSyncEnabled.
  • Only 100 results? Add -All to page through everything.
  • 403 Forbidden? The token lacks a scope, or the signed-in user lacks the directory role. Check (Get-MgContext).Scopes and reconnect.
  • No cmdlet for it? Invoke-MgGraphRequest -Method GET -Uri "v1.0/..." calls any endpoint with your existing connection.
  • What did it send? Add -Debug to see the HTTP request and response.