Microsoft 365 PowerShell Command Catalog

Find the right Microsoft 365 PowerShell command.
First time, every time.

I built this because I couldn't find it anywhere: an interactive catalog of Exchange Online, Entra ID, Intune, Teams, SharePoint, Security and Purview commands that actually explains when and why you'd use each one. Not a bare cmdlet list, not a docs page with no use case, and not an AI spitting out commands you'll never remember. Search by problem, fill in the fields, copy the right command, and stay sharp doing it.

Open Exchange Builder View all tools
310+Commands
50+Categories
8Catalogs live
19Tools & guides
0Data logged
FreeAlways

Catalogs
Command catalogs

Browse by category or search by problem. Every command includes a description, a real-world scenario and a risk label.

Live

Exchange Online

130+ commands across mailboxes, calendars, shared mailboxes, permissions, message trace, anti-spam, quarantine, mobile devices and more.

130+ commands 15 categories syntax checker
Live

Entra ID

70+ commands covering users, licensing, groups, admin roles, sign-in logs, MFA methods, devices and Conditional Access via Microsoft Graph PowerShell. Every command lists its required scopes.

70+ commands graph scopes syntax checker
Live

Intune

29 commands covering managed devices, remote actions (wipe, retire, sync, lock), compliance, configuration profiles, apps and Autopilot via Microsoft Graph PowerShell. Each lists its required scopes.

29 commands remote actions graph scopes
Live

Teams

23 commands covering teams and channels, membership, meeting and messaging policies, external access and Teams Phone voice (numbers, routing, resource accounts) via the MicrosoftTeams module.

23 commands voice / phone syntax checker
Live

SharePoint & OneDrive

24 commands covering site collections, storage reports, OneDrive access, external sharing and permissions via PnP PowerShell. Sites, sharing posture and leaver OneDrive retrieval in one place.

24 commands PnP PowerShell sharing audit
Live

Security & Defender

19 commands for incident and alert triage, Safe Links and Safe Attachments, risky users and risk detections, restricted senders after compromise, and Secure Score. Spans Graph Security and Exchange Online.

19 commands incident triage compromise response
Live

Purview Audit & Compliance

17 commands for the unified audit log (who deleted email, who changed admin roles, inbox-rule compromise hunting, file-download exfiltration), plus litigation holds, retention policies and eDiscovery cases.

17 commands audit search compromise hunting
Live

Offline catalog

Six catalogs (Exchange, Entra ID, Intune, Teams, SharePoint, Security) in one self-contained page. Build and search commands across them all, and download the page as a single HTML file that works with no internet on locked-down client servers.

6 catalogs downloadable works offline

Tools
Interactive tools

Paste-and-decode utilities and builders. Everything runs client-side in your browser.

Live

Incident Response Builder

Enter a UPN, pick a scenario (account compromise, BEC, OAuth abuse, risky sign-in, leaver offboarding, phishing cleanup, admin compromise), and get a sequenced runbook of copy-paste commands with risk labels.

7 scenarios live UPN fill copy all as script
Live

AADSTS error decoder

Enter an Entra ID sign-in error code like AADSTS50126 or paste the full error message. Get the plain-English meaning, the likely causes, and the sign-in log command to find every occurrence. 40+ codes catalogued.

client-side sign-in errors
Live

CA policy explainer

Paste the JSON of a Conditional Access policy and get a plain-English readout: who it targets, what it demands, every exclusion, and common misconfigurations flagged. Entirely client-side.

client-side misconfig flags
Live

SMTP header analyser

Paste message headers, get a hop timeline with per-hop delays, SPF, DKIM, DMARC and compauth verdicts, SCL spam scoring and sender mismatch flags. Entirely client-side.

client-side phishing triage
Live

NDR / bounce decoder

Enter a 4.x.x or 5.x.x status code or paste a whole non-delivery report. Get the meaning, the likely Exchange Online causes and where to look next. 70+ codes catalogued.

client-side mail flow
Live

Email auth analyser

Paste an SPF, DKIM or DMARC record for a plain-English breakdown with faults flagged: multiple SPF records, the 10-lookup limit, weak DMARC policies, revoked DKIM keys.

SPF / DKIM / DMARC no DNS calls

Guides
Guides

Written companions to the catalogs: step-by-step procedures for the situations the commands are built for.

Live

Connection setup guide

Exchange Online V3 and Microsoft Graph PowerShell: install, MFA sign-in, GDAP delegated access, app-only certificate auth, and the common connection errors decoded.

EXO + Graph error table
Live

Mail flow triage guide

"A user says their email is missing." A step-by-step decision tree from inbound-vs-outbound through trace, quarantine, inbox rules and NDR codes, tying together the trace commands and the email tools.

decision tree missing email
Live

DKIM and DMARC setup

Enabling DKIM signing in Exchange Online, publishing a DMARC record safely, auditing third-party senders, moving from p=none to p=reject without breaking legitimate mail, and common setup errors.

DNS records enforcement rollout
Live

Hybrid mail flow

Diagnosing connector failures, certificate mismatches, cloud-to-on-premises routing via MailUser, and public folder coexistence including the stale RemotePublicFolderMailbox GUID fix.

connectors public folders
Live

Account compromise response

Contain first, investigate second. Revoke sessions, audit inbox rules and forwarding, review sign-in logs, check MFA methods, trace what the attacker sent, and review OAuth consents granted.

BEC response session revocation
Live

Retention policies and holds

How retention policies, retention labels and litigation hold interact, what a mailbox on hold actually looks like, Recoverable Items quota problems, and the inactive mailbox offboarding pattern.

litigation hold Purview
Live

Sign-in triage guide

"A user can't sign in." A decision tree from the sign-in log through the AADSTS code to the right branch: credentials, MFA, Conditional Access, device state or app configuration, with the PowerShell at each step.

decision tree AADSTS codes
Live

SharePoint access-denied triage

"Access denied" layer by layer: sign-in vs permission failures, site membership, broken inheritance, sharing links, external sharing settings and OneDrive cases, with the PnP PowerShell at each step.

decision tree permissions
Live

Conditional access baseline

Break-glass accounts first, then the four baseline policies in deployment order: block legacy auth, require MFA for all users, protect admins, and compliant device. Named locations and What If testing.

MSP baseline break-glass

Reference
References

Lookup tables: what changed, what replaced it, and what the SKU names actually mean.

Live

Cmdlet migration guide

Deprecated Exchange Online and Entra ID cmdlets and their replacements: message trace V2, unified audit log, the EXO cmdlets, and MSOnline / AzureAD to Graph.

40+ mappings working examples
Live

Licence SKU reference

What SPE_E3, O365_BUSINESS_PREMIUM and 50+ other SkuPartNumber values actually mean, including the renaming traps, with a filterable lookup.

60+ SKUs filterable
Live

Graph scopes reference

Which Microsoft Graph permission scope you need for which admin task: users, sign-in logs, devices, Conditional Access, risk and consent. Filterable, with the least-privilege rules explained.

40+ scopes filterable
Live

GDAP role reference

The minimum delegated admin role for common MSP tasks: password resets, MFA resets, quarantine, Intune, Conditional Access and compliance search, plus the pitfalls that generate tickets.

least privilege filterable

Features
How the catalog works

Designed around the actual situations MSP engineers face day to day.

Search

Search by problem

Type a concept like "leaver offboarding" or "missing email" and get every relevant command ranked by relevance.

Browse

Browse by category

Commands organised into 50+ categories across all seven product catalogs, from Exchange Online to Purview.

Risk labels

Risk-aware

Every command is labelled read-only, config change, removes data or wipes device. Destructive actions require confirmation before copying.

Descriptions

Real-world context

Each command includes a plain-English description and a realistic MSP scenario so you know exactly when to use it.

Validator

Simulated syntax check

Paste commands into the console tab to check parameter names and structure before running against a live tenant.

No login

Nothing is stored

Everything runs in your browser. No backend, no database, no logging. Nothing leaves your machine.


Why this catalog exists

Exchange Online PowerShell has hundreds of cmdlets. Remembering the exact parameter names, correct syntax and which commands are safe versus destructive while working on a live client tenant is genuinely difficult.

This is a reference catalog for MSP engineers who know what they need to do but want to get the command right without trial and error on a production environment.

Free, runs entirely in the browser, logs nothing.

# common MSP scenarios Get-EXOMailbox -ResultSize Unlimited full tenant mailbox inventory Get-MessageTraceV2 -RecipientAddress ... trace missing inbound email Set-Mailbox -Identity ... -Type Shared convert leaver mailbox Connect-ExchangeOnline -DelegatedOrg ... MSP delegated tenant access Get-QuarantineMessage -PageSize 100 check held messages Clear-MobileDevice -Identity ... remote wipe stolen device