Microsoft 365 Evidence Snapshot
Read-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.
No account and no email required. The optional email copy is available below.
How to use it
A working starting point, with the limits stated.
A compact evidence starter for operators who need repeatable Microsoft 365 posture snapshots without changing tenant configuration. The examples export Secure Score and licensed-user findings locally, while the KQL query provides a bounded failed sign-in starting point.
- Copy the files into an organisation-owned repository.
- Replace placeholders and name accountable owners.
- Review permissions, thresholds and approval points.
- Test in a controlled window and retain the evidence.
Scope note
Exports can contain personal and security data. Confirm authority, Graph permissions, storage and retention before use.
Templates are operating aids. They are not certification, legal advice or a claim that a target environment is secure.
Want a copy in your inbox?
Optional email delivery makes the link easy to recover. You can download above without submitting anything.
This request does not subscribe you to the Ops Log newsletter.