All tools

Cloud

GraphRunner

PowerShell toolkit for exploring what a Microsoft Graph identity can see in an authorized review.

advanced
Windows
PowerShell
Enumeration

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Authorized identities and tenants only. Do not use found tokens.

When

You need to understand Graph permissions already granted to an identity the engagement is allowed to review.

How

Use the name in a report when an inventory of Graph access is in scope. This page does not include commands or tokens.

Why

Application and delegated Graph permissions are a common place for overly broad access.

Commands & usage

# Descriptive only. No commands and no tokens on this page.
# See the Identity, SSO and Entra ID module for how to scope the work.

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

graph
entra
identity
oauth

Related in Cloud