Outdated PowerShell Script for Security Forensics

Occasional Visitor

Hi All, 

 

Recently, we had a client experience a security incident and had the need to run the PowerShell Script in the below article "Get-AllTenantRulesAndForms.ps1" from GitHub. After running and reviewing the script, it appears to be attempting use basic authentication which has been disabled by Microsoft starting October 2022. We attempted to update the connection to modern authentication which was successful and connected however the subsequent commands that query the mailboxes still returns 401 unauthorized with the correct permissions applied to the administrator account. Does anyone know if this script will be updated to properly use modern authentication?

 

https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/detect-and-remediate-ou...

 

Thanks, 
Robert Padilla

1 Reply

@rpadilla-ics Normally I would suggest opening up an issue on the GitHub page, but...

 

Harm_Veenstra_0-1669734815644.png