Releases: bilozorDev/microsoft-mgmt-cli
Releases · bilozorDev/microsoft-mgmt-cli
Release list
v3.0.0
What's New
- Renamed "Emergency Response" → "Compromised Account" workflow
- Excel mail flow reports — replaces console message trace with two Excel files (sent-by, sent-to) covering the last 10 days
- Sign-in log Excel report — new sub-menu option fetching last 7 days of sign-in activity via Graph REST API
- Admin role check — warns if the compromised user holds admin roles so responders know to review tenant-wide changes
- Delegation removal — audit mailbox permissions now offers a multiselect to remove FullAccess, SendAs, and SendOnBehalf
- Human-readable ticket notes — replaced checkbox format with natural language prose, only includes actions actually taken
- Password delivery tracking — ticket notes correctly reflect whether credentials were shared via one-time secret link or raw password fallback
v2.1.0
What's New
- User Info command — view a user's roles, licenses, mailbox size, and 2FA methods from User Management
- Telemetry & Analytics — added Sentry error tracking and PostHog analytics for usage insights
- Improved error handling — all commands now wrapped in consistent error handling with tracking
Full Changelog
v2.0.0
What's New
Email Security Commands
- Block sender/domain(s) — block senders or entire domains
- Quarantine management — review and manage quarantined messages
- Message trace — trace email delivery
- DKIM / Email authentication — audit DKIM, SPF, and DMARC configuration
Emergency Response
- Compromised account workflow — guided response for compromised accounts
Multi-Tenant Auth Fix
-DisableWAMon Windows prevents OS-level cached account auto-selection- Tenant ID pinning — extracts tenant ID from Exchange Online and passes it to Graph via
-TenantId -ContextScope Process— isolates Graph tokens to the current process (no shared cache)- Tenant mismatch detection — verifies Graph connected to the same tenant as Exchange Online
Other Changes
- Refactored Graph scope system to per-scope tracking with automatic upgrades
- Reorganized menu: "Spam Management" → "Email Security"
v1.10.0
What's New
- Change primary domain in edit-user — move a user to a different domain, old address preserved as alias
- Add email alias in edit-user — add additional email addresses to a user's mailbox
- License status hints — user pickers in edit-user and delete-user now show "(not licensed)" for unlicensed users
- Ticket notes — domain changes and added aliases are included in the copy-to-clipboard ticket note
- Fix JSON parse error on second user creation by synchronizing PS output
v1.9.1
v1.9.0
What's New
-
Calendar reminders for license renewals — After exporting the license report to Excel, you can now create
.icscalendar reminder files for upcoming subscription renewals. Files open natively in Outlook with a 7-day advance reminder and include the tenant domain in the event summary. -
Ticket notes for group creation — Distribution group, security group, and shared mailbox creation now offer a "Copy ticket update note" clipboard option summarizing the created resource and any added members/owners/permissions.
v1.8.0
Security Hardening
- Auto-updater integrity verification: Downloads are now verified against a SHA-256 checksum. If the checksum doesn't match, the update is aborted. If no checksum is available (older releases), the user is prompted to confirm.
- Fixed version comparison: The auto-updater now uses proper semver comparison instead of string comparison (e.g.,
1.9.0was incorrectly considered less than1.10.0). - Least-privilege Graph API scopes: Read-only operations (reports, audits) now request only
*.Read.Allscopes. Write scopes are only requested when performing mutations (create/edit/delete users, groups). - Restrictive file permissions on reports: Exported Excel reports are now created with
0o600(owner read/write only) and report directories with0o700. - Consistent PowerShell escaping: All PowerShell string interpolation now uses the centralized
escapePS()helper.
v1.7.0
What's New
- OTS link fix: Switched from
us.onetimesecret.com(broken) toeu.onetimesecret.com - OTS error visibility: Actual error messages are now shown instead of a generic failure message
- OTS security: One-time secret links now contain only the password, not the email
- Edit user — OTS & ticket notes: Password resets now generate an OTS link and offer clipboard options for the link and a ticket update note
- Ticket note formatting: Notes read naturally (e.g. "Reset password for Jane Doe") with groups listed individually with emails
- Graph scope: Added
User-PasswordProfile.ReadWrite.Allfor password reset support - Create user — clipboard options: "Copy OTS link" and "Copy ticket update note" moved to the post-creation menu
v1.5.0
What's New
- Licensed Users Report — new report under Reports menu showing all licensed users with friendly license names. Optionally enrich with:
- Mailbox size (GB/MB)
- MFA methods (Authenticator, Phone, FIDO2, etc.)
- Admin role assignments
- Terminal preview (first 50 rows) + Excel export with blank Notes column for manual use
v1.4.0
Groups & Shared Mailbox Management
New top-level menu for managing distribution groups, security groups, and shared mailboxes:
- Create groups/mailboxes with members, owners, and permissions
- Edit existing groups (rename, add/remove members/owners/permissions)
- Delete groups with detail display and confirmation
Other improvements
- Migrated to EXO v3 cmdlets for better performance
- Migrated to documented Graph
ByRefAPIs - User lists now filter out shared mailbox accounts and unlicensed users
- Added
Group.ReadWrite.AllGraph scope for security group operations