syne0 / osprey

Powershell Based tool for gathering information related to O365 intrusions and potential Breaches
MIT License
6 stars 2 forks source link

Flag admins created during investigation period #44

Closed syne0 closed 2 months ago

syne0 commented 2 months ago

technically it already flags users but if you have a lot of users added an investigator may miss an admin. so, add flag for new admins to Get-OspreyTenantEntraAdmins.ps1.