azureblog.co.uk
← cd ~/tools
// tools/health

Tenant health check

A quick security review of your Entra ID tenant: MFA coverage, Conditional Access, admin roles, guests, consent settings, app credentials and more.

How it works

  1. Download the script. It's read-only, makes no changes, and you can read every line first.
  2. Run it in PowerShell, signed in as a Global Reader. It needs the Microsoft Graph PowerShell module.
    powershell
    Install-Module Microsoft.Graph -Scope CurrentUser   # first time only
    .\Get-AzureBlogHealthCheck.ps1
  3. Load the result here. It saves azureblog-health-<date>.json. The file holds counts and settings only: no names, emails or IDs. It's read in your browser and never uploaded.

Drop your azureblog-health-….json file here

Some checks need Entra ID P1 or P2. They're skipped, with a note, if your tenant doesn't have them.