← cd ~/learn
azureblog.co.uk · cheat sheet
Microsoft Graph PowerShell essentials
Connecting, finding the right cmdlet and permission, filtering and paging: the commands you'll use every day.
Fits on one A4 page. Checked 9 Oct 2026.
Install and connect
Install-Module Microsoft.Graph -Scope CurrentUser
Install-Module Microsoft.Graph.Beta -Scope CurrentUser # beta cmdlets
Connect-MgGraph -Scopes "User.Read.All","Group.Read.All"
Get-MgContext # who and which scopes
Disconnect-MgGraph
Unattended
# App registration with a certificate
Connect-MgGraph -ClientId $appId -TenantId $tenantId `
-CertificateThumbprint $thumb
# Managed identity (Automation, Functions, VMs)
Connect-MgGraph -Identity
Find the cmdlet and permission
Find-MgGraphCommand -Command Get-MgUser | Select -First 1 -Expand Permissions
Find-MgGraphCommand -Uri "/users/{id}/memberOf"
Find-MgGraphPermission user -PermissionType Delegated
Moving from MSOnline or AzureAD? Use the cmdlet translator.
Filter, select, page
Get-MgUser -All -Filter "accountEnabled eq true" `
-Property DisplayName,UserPrincipalName,SignInActivity
# Advanced queries need eventual consistency and a count
Get-MgUser -Filter "endsWith(mail,'@contoso.com')" `
-ConsistencyLevel eventual -CountVariable n -All
Get-MgGroupMember -GroupId $gid -All
Gotchas
- Missing properties? Most cmdlets return a default set. Ask for others with
-Property, for exampleSignInActivityorOnPremisesSyncEnabled. - Only 100 results? Add
-Allto page through everything. - 403 Forbidden? The token lacks a scope, or the signed-in user lacks the directory role. Check
(Get-MgContext).Scopesand reconnect. - No cmdlet for it?
Invoke-MgGraphRequest -Method GET -Uri "v1.0/..."calls any endpoint with your existing connection. - What did it send? Add
-Debugto see the HTTP request and response.