Pick a scenario. Enter the affected account. Get a sequenced runbook of copy-paste PowerShell commands with risk labels.