how to query entra id for a user's group memberships with powershell
Queries Microsoft Entra ID group memberships with PowerShell via Microsoft Graph. Covers connection, the query, and nested groups. Use for access investigations. Not for AD on-prem groups (use Get-ADPrincipalGroupMembership).
TL;DR
Connect with Connect-MgGraph, then run Get-MgUserMemberOf -UserId [recipient email] (replace with the real UPN) to list direct memberships. For nested groups, recurse through each group's own memberships. The Graph SDK is the modern path; the old MSOnline module is deprecated.
The error
(Investigation; no error.)Steps
- Install and connect:
Install-Module Microsoft.Graphonce, thenConnect-MgGraph -Scopes "User.Read.All","Group.Read.All". Expected: connected. Consent the permissions on first use. - List direct memberships:
Get-MgUserMemberOf -UserId [recipient email] | Select DisplayName. Expected: groups listed. Note this shows direct memberships only. - For nested: for each group, run
Get-MgGroupMemberOf -GroupId [id]and recurse. Expected: full chain. Or check the user's transitive membership via the Graph$filterendpoints. - Filter to the interesting types: security groups vs distribution lists vs roles. Expected: typed list. The access question usually concerns security groups.
- Document the membership path in the ticket. Expected: recorded.
When to use
- Entra access investigations
- Pre-offboarding access inventory
When not to use
- On-prem AD groups (use the AD cmdlets)
- Real-time provisioning (use the admin centers)
Compatibility
- Microsoft Graph PowerShell SDK; Entra ID
Variants
One-liner for direct memberships
Get-MgUserMemberOf -UserId [upn] -All | ForEach { $_.AdditionalProperties.displayName }
Checking a group's members
Get-MgGroupMember -GroupId [id] for the reverse direction.
Why it happens
Entra has no whoami /groups equivalent on the client; the Graph API is the query path. Membership questions that took seconds in AD need the SDK in Entra.
Edge cases
- The old MSOnline/AzureAD modules are deprecated; do not build new workflows on them.
- Large tenants: page through results with
-All; default pages are small.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ZWriwTe5FMIPSg0Y2fuzrA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.