M365IdentityPosture
1.0.0
Current Release (v1.0): Authentication Context Inventory
- Complete discovery and analysis of authentication context usage across all Microsoft 365 services
- Purview sensitivity labels with embedded authentication requirements
- Condit
Current Release (v1.0): Authentication Context Inventory
- Complete discovery and analysis of authentication context usage across all Microsoft 365 services
- Purview sensitivity labels with embedded authentication requirements
- Conditional Access policies referencing authentication contexts
- Privileged Identity Management (PIM) policies for directory roles, groups, and Azure resources
- SharePoint sites with direct or inherited authentication context assignments
- Microsoft 365 Groups and Teams with context-enforcing sensitivity labels
- Protected actions (RBAC) requiring authentication contexts
- Cross-service correlation with rich HTML reporting and metrics dashboard
Designed as an extensible framework for future identity and security analytics including Access Package reporting,
Role Assignment auditing, Conditional Access gap analysis, and Identity Protection insights.
Minimum PowerShell version
7.0
Installation Options
Owners
Copyright
(c) 2025 Sebastian Flæng Markdanner. All rights reserved.
Package Details
Author(s)
- Sebastian Flæng Markdanner
Tags
Microsoft365 M365 Reporting AuthenticationContext ConditionalAccess MicrosoftGraph Azure EntraID AzureAD PIM PrivilegedIdentityManagement Purview SensitivityLabels SharePoint SharePointOnline SPO Teams MicrosoftTeams Security Compliance Governance IdentityGovernance ZeroTrust RBAC
Functions
Invoke-AuthContextInventoryReport
PSEditions
Dependencies
This module has no dependencies.
Release Notes
## Version 1.0.0 - 2025-10-21
Initial release of M365IdentityPosture module
### Features
- Authentication Context inventory across all Microsoft 365 services
- Purview sensitivity label analysis with authentication context detection
- Conditional Access policy mapping and analysis
- Privileged Identity Management (PIM) comprehensive coverage:
- Directory role management policies
- Group-based PIM with role assignments
- Azure resource PIM (optional)
- SharePoint Online direct and inherited context detection
- Microsoft 365 Groups/Teams label inheritance tracking
- Protected actions (RBAC) authentication requirements
- Rich HTML reporting with runtime theme switching
- Cross-service correlation and metrics dashboard
### Technical Highlights
- PowerShell 7+ cross-platform support
- Dynamic module loading for optimal performance
- Comprehensive error handling and logging
- Memory-efficient processing for large tenants
- Modular architecture for future expansion
### Requirements
- PowerShell 7.0 or later
- Microsoft Graph and service-specific modules (auto-loaded)
- Global Reader or equivalent permissions
### Known Limitations
- Read-only operations (no tenant modifications)
- Azure PIM requires subscription-level access
- Large tenant processing may take extended time
For complete documentation, visit:
https://github.com/Noble-Effeciency13/M365IdentityPosture
FileList
- M365IdentityPosture.nuspec
- Private\Orchestration\Invoke-GracefulCleanup.ps1
- CHANGELOG.md
- Private\AuthContext\DataCollection\Get-AuthContextLabels.ps1
- Private\Authentication\Connect-GraphSafe.ps1
- Private\Orchestration\Invoke-GraphPhase.ps1
- CONTRIBUTING.md
- Private\AuthContext\DataCollection\Get-ConditionalAccessPoliciesWithAuthContext.ps1
- Private\Authentication\Connect-PurviewService.ps1
- Private\Orchestration\Invoke-GroupPhase.ps1
- LICENSE
- Private\AuthContext\DataCollection\Get-DirectoryPIMPoliciesFiltered.ps1
- Private\Authentication\Connect-SharePointAdmin.ps1
- Private\Orchestration\Invoke-Preflight.ps1
- Private\AuthContext\DataCollection\Get-EntraPIMPPoliciesWithAuthContext.ps1
- Private\Authentication\Connect-SPOServiceSafe.ps1
- Private\Orchestration\Invoke-PurviewPhase.ps1
- M365IdentityPosture.psd1
- Private\AuthContext\DataCollection\Get-GroupPIMPoliciesFiltered.ps1
- Private\Authentication\Invoke-ModuleOperation.ps1
- Private\Orchestration\Invoke-SharePointPhase.ps1
- M365IdentityPosture.psm1
- Private\AuthContext\DataCollection\Get-GroupPIMPoliciesForManagedGroups.ps1
- Private\DataCollection\Get-AllGroupsMinimal.ps1
- Private\ReportGeneration\Convert-DataTableHtml.ps1
- README.md
- Private\AuthContext\DataCollection\Get-LabelledUnifiedGroups.ps1
- Private\DataCollection\Get-AzureResourcePIMPolicies.ps1
- Private\ReportGeneration\New-AuthContextHtmlReport.ps1
- .github\workflows\publish-psgallery.yml
- Private\AuthContext\DataCollection\Get-PIMManagedGroupsResources.ps1
- Private\DataCollection\Get-GraphTenantMetadata.ps1
- Private\Utilities\Import-AzAccountsModule.ps1
- .vscode\settings.json
- Private\AuthContext\DataCollection\Get-PIMPoliciesWithAuthContext.ps1
- Private\DataCollection\Get-PurviewLabelsRaw.ps1
- Private\Utilities\Import-GraphModules.ps1
- Private\AuthContext\Connection\Finalize-AzurePhase.ps1
- Private\AuthContext\DataCollection\Get-ProtectedActionsWithAuthContext.ps1
- Private\DataCollection\Get-SPOSitesRaw.ps1
- Private\Utilities\Import-SharePointModule.ps1
- Private\AuthContext\Core\Convert-PIMPoliciesToAuthContext.ps1
- Private\AuthContext\DataCollection\Invoke-AzureResourcePIMCollection.ps1
- Private\DataProcessing\Expand-PurviewLabelsIfNeeded.ps1
- Private\Utilities\Use-ScopedModules.ps1
- Private\AuthContext\Core\Filter-SitesForAuthContext.ps1
- Private\AuthContext\Processing\Parse-PurviewLabelsForAuthContext.ps1
- Private\DataProcessing\Resolve-DirectoryRoleName.ps1
- Public\Invoke-AuthContextInventoryReport.ps1
- Private\AuthContext\Core\Get-AuthenticationContexts.ps1
- Private\AuthContext\Processing\Resolve-AndProjectPIMPolicies.ps1
- Private\Orchestration\Invoke-AuthContextInventoryCore.ps1
- Private\AuthContext\Core\SanitizeAuthContextText.ps1
- Private\Authentication\Connect-AzContextSafe.ps1
- Private\Orchestration\Invoke-AzurePhase.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 1.0.0 (current version) | 6 | 10/21/2025 |