Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses

Executive Summary

The article explains how attackers can use Microsoft Graph API and PowerShell to enumerate stale user accounts and unused licenses in Microsoft 365 environments. It details the API endpoints, authentication, and scripts that retrieve user and license data, highlighting the risk of privileged data exposure and the need for proper monitoring.


Intelligence Metadata - Source Publisher: SANS Internet Storm Center - Published Date: 2026-08-20T12:45:32+00:00 - Category: threat-intel

Original Description: Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet.&#;x26;#;xc2;&#;...

"Every human being is the author of his own health or disease."

— Buddha
Source: SANS Internet Storm Center