PowerShell#
Connect-MgGraph -Scopes 'User.Read.All'
Get-MgUser -Filter "accountEnabled eq true" -Property DisplayName,UserPrincipalName |
Select-Object DisplayName, UserPrincipalName
KQL#
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType != 0
| summarize Failures = count() by UserPrincipalName, AppDisplayName
| top 10 by Failures desc
JSON#
{
"displayName": "Require MFA for admins",
"state": "enabledForReportingButNotEnforced"
}
Table#
| Product | Role |
|---|
| Entra ID | Cloud identity |
| Intune | Device management |
| Defender | Endpoint/identity XDR |
Image#
