Commands › Exchange Online

Test-ServicePrincipalAuthorization

Exchange Online ExchangeOnlineManagement Test-*

Test the access granted by role-based access control (RBAC) for Applications. For more information, see Role Based Access Control for Applications in Exchange Online.

Quick start script

# Test-ServicePrincipalAuthorization — quick start (serv365.ai)
# 1. Connect (app-only shown; interactive: omit the certificate parameters)
Connect-ExchangeOnline -CertificateThumbprint $thumb -AppId $appId -Organization $org

# 2. Run and inspect
Test-ServicePrincipalAuthorization -Identity <ServicePrincipalIdParameter> | Format-List

# 3. Export for evidence / drift tracking
Test-ServicePrincipalAuthorization | Export-Clixml .\ServicePrincipalAuthorization-$(Get-Date -Format yyyyMMdd).xml

Syntax

Test-ServicePrincipalAuthorization [-Identity] <ServicePrincipalIdParameter>
 [-Confirm]
 [-Resource <UserIdParameter>]
 [-WhatIf]
 [<CommonParameters>]

Parameters (4)

ParameterTypeRequiredWhat it controls
-Identity ServicePrincipalIdParameter yes The Identity parameter specifies the service principal that you want to test. You can use any value that uniquely identifies the service principal. For example:
-Confirm SwitchParameter This parameter is reserved for internal Microsoft use.
-Resource UserIdParameter The Resource parameter specifies the target mailbox where the scoped permissions apply. You can use any value that uniquely identifies the mailbox. For example:
-WhatIf SwitchParameter This parameter is reserved for internal Microsoft use.

Reference facts derived from Microsoft documentation, © Microsoft, licensed CC BY 4.0; restructured with original guidance by serv365.ai.