I built this because I couldn't find it anywhere: an interactive catalog of Exchange Online, Entra ID, Intune, Teams, SharePoint, Security and Purview commands that actually explains when and why you'd use each one. Not a bare cmdlet list, not a docs page with no use case, and not an AI spitting out commands you'll never remember. Search by problem, fill in the fields, copy the right command, and stay sharp doing it.
Browse by category or search by problem. Every command includes a description, a real-world scenario and a risk label.
130+ commands across mailboxes, calendars, shared mailboxes, permissions, message trace, anti-spam, quarantine, mobile devices and more.
70+ commands covering users, licensing, groups, admin roles, sign-in logs, MFA methods, devices and Conditional Access via Microsoft Graph PowerShell. Every command lists its required scopes.
29 commands covering managed devices, remote actions (wipe, retire, sync, lock), compliance, configuration profiles, apps and Autopilot via Microsoft Graph PowerShell. Each lists its required scopes.
23 commands covering teams and channels, membership, meeting and messaging policies, external access and Teams Phone voice (numbers, routing, resource accounts) via the MicrosoftTeams module.
24 commands covering site collections, storage reports, OneDrive access, external sharing and permissions via PnP PowerShell. Sites, sharing posture and leaver OneDrive retrieval in one place.
19 commands for incident and alert triage, Safe Links and Safe Attachments, risky users and risk detections, restricted senders after compromise, and Secure Score. Spans Graph Security and Exchange Online.
17 commands for the unified audit log (who deleted email, who changed admin roles, inbox-rule compromise hunting, file-download exfiltration), plus litigation holds, retention policies and eDiscovery cases.
Six catalogs (Exchange, Entra ID, Intune, Teams, SharePoint, Security) in one self-contained page. Build and search commands across them all, and download the page as a single HTML file that works with no internet on locked-down client servers.
Paste-and-decode utilities and builders. Everything runs client-side in your browser.
Enter a UPN, pick a scenario (account compromise, BEC, OAuth abuse, risky sign-in, leaver offboarding, phishing cleanup, admin compromise), and get a sequenced runbook of copy-paste commands with risk labels.
Enter an Entra ID sign-in error code like AADSTS50126 or paste the full error message. Get the plain-English meaning, the likely causes, and the sign-in log command to find every occurrence. 40+ codes catalogued.
Paste the JSON of a Conditional Access policy and get a plain-English readout: who it targets, what it demands, every exclusion, and common misconfigurations flagged. Entirely client-side.
Paste message headers, get a hop timeline with per-hop delays, SPF, DKIM, DMARC and compauth verdicts, SCL spam scoring and sender mismatch flags. Entirely client-side.
Enter a 4.x.x or 5.x.x status code or paste a whole non-delivery report. Get the meaning, the likely Exchange Online causes and where to look next. 70+ codes catalogued.
Paste an SPF, DKIM or DMARC record for a plain-English breakdown with faults flagged: multiple SPF records, the 10-lookup limit, weak DMARC policies, revoked DKIM keys.
Written companions to the catalogs: step-by-step procedures for the situations the commands are built for.
Exchange Online V3 and Microsoft Graph PowerShell: install, MFA sign-in, GDAP delegated access, app-only certificate auth, and the common connection errors decoded.
"A user says their email is missing." A step-by-step decision tree from inbound-vs-outbound through trace, quarantine, inbox rules and NDR codes, tying together the trace commands and the email tools.
Enabling DKIM signing in Exchange Online, publishing a DMARC record safely, auditing third-party senders, moving from p=none to p=reject without breaking legitimate mail, and common setup errors.
Diagnosing connector failures, certificate mismatches, cloud-to-on-premises routing via MailUser, and public folder coexistence including the stale RemotePublicFolderMailbox GUID fix.
Contain first, investigate second. Revoke sessions, audit inbox rules and forwarding, review sign-in logs, check MFA methods, trace what the attacker sent, and review OAuth consents granted.
How retention policies, retention labels and litigation hold interact, what a mailbox on hold actually looks like, Recoverable Items quota problems, and the inactive mailbox offboarding pattern.
"A user can't sign in." A decision tree from the sign-in log through the AADSTS code to the right branch: credentials, MFA, Conditional Access, device state or app configuration, with the PowerShell at each step.
"Access denied" layer by layer: sign-in vs permission failures, site membership, broken inheritance, sharing links, external sharing settings and OneDrive cases, with the PnP PowerShell at each step.
Break-glass accounts first, then the four baseline policies in deployment order: block legacy auth, require MFA for all users, protect admins, and compliant device. Named locations and What If testing.
Lookup tables: what changed, what replaced it, and what the SKU names actually mean.
Deprecated Exchange Online and Entra ID cmdlets and their replacements: message trace V2, unified audit log, the EXO cmdlets, and MSOnline / AzureAD to Graph.
What SPE_E3, O365_BUSINESS_PREMIUM and 50+ other SkuPartNumber values actually mean, including the renaming traps, with a filterable lookup.
Which Microsoft Graph permission scope you need for which admin task: users, sign-in logs, devices, Conditional Access, risk and consent. Filterable, with the least-privilege rules explained.
The minimum delegated admin role for common MSP tasks: password resets, MFA resets, quarantine, Intune, Conditional Access and compliance search, plus the pitfalls that generate tickets.
Designed around the actual situations MSP engineers face day to day.
Type a concept like "leaver offboarding" or "missing email" and get every relevant command ranked by relevance.
Commands organised into 50+ categories across all seven product catalogs, from Exchange Online to Purview.
Every command is labelled read-only, config change, removes data or wipes device. Destructive actions require confirmation before copying.
Each command includes a plain-English description and a realistic MSP scenario so you know exactly when to use it.
Paste commands into the console tab to check parameter names and structure before running against a live tenant.
Everything runs in your browser. No backend, no database, no logging. Nothing leaves your machine.
Exchange Online PowerShell has hundreds of cmdlets. Remembering the exact parameter names, correct syntax and which commands are safe versus destructive while working on a live client tenant is genuinely difficult.
This is a reference catalog for MSP engineers who know what they need to do but want to get the command right without trial and error on a production environment.
Free, runs entirely in the browser, logs nothing.