Microsoft Graph PowerShell SDK
FreeThe supported way to script Entra ID, Intune, and most of Microsoft 365 now that the MSOnline and AzureAD modules are retired.
If an old guide tells you to run Connect-MsolService, this is what replaces it.
Most of the best Microsoft 365 tooling is free. These are the tools I open on real projects, with a few paid picks I'd recommend to a colleague without hesitation.
The supported way to script Entra ID, Intune, and most of Microsoft 365 now that the MSOnline and AzureAD modules are retired.
If an old guide tells you to run Connect-MsolService, this is what replaces it.
Mailbox permissions, mail flow, migration batches, and everything the Exchange admin center hides three menus deep.
You'll need it for almost every email runbook on this site.
Microsoft's IntuneWinAppUtil.exe. It packages any installer into the .intunewin format Intune needs for Win32 apps.
Always grab the latest release. Old versions produce packages that fail silently.
Collects a device's hardware hash and, with -Online, uploads it straight to your tenant. It's the fastest way to register existing PCs for Autopilot.
Use it for existing hardware. For new hardware, have your reseller register devices instead.
A PowerShell test framework that checks your Entra ID and Microsoft 365 configuration against security best practices and produces a readable HTML report.
Great for a before-and-after snapshot around any hardening project.
CISA's assessment tool for its Microsoft 365 secure configuration baselines, covering Entra ID, Exchange Online, Defender, Teams, and SharePoint.
Built for government baselines, so treat the results as a to-do list, not a pass/fail grade.
Built into the Defender portal. It scores your tenant's security posture and links each recommendation to the setting that fixes it.
Useful for prioritizing work. Don't chase 100%, because some recommendations won't fit your business.
Microsoft's own tester for Autodiscover, inbound and outbound SMTP, and Teams connectivity from outside your network.
Paste in raw message headers to see every hop, delay, and SPF/DKIM/DMARC verdict. It's the fastest way to answer "why did this land in junk?"
Quick lookups for MX, SPF, DKIM, DMARC, and blacklist status. I check it before and after every DNS change during a migration.
Layered endpoint protection with AV, EDR, risk analytics, and patch management in one cloud console, with lightweight agents and a strong multi-tenant story for MSPs.
A solid choice for environments that aren't licensed for Defender for Business, or that need more reporting than it offers.
Business VPN with centralized management, dedicated IPs, and site-to-site connectivity. It secures remote workers on untrusted networks without standing up your own VPN server.
A practical pick for small teams that need remote access security without the overhead.
The best way to run Windows 11 on Apple Silicon. You get full Windows admin tooling (PowerShell, RSAT, MMC snap-ins) on a MacBook with no dual-boot.
It's how I run a Windows admin workstation on my Mac every day.
Affiliate disclosure: Links marked "Affiliate" may earn me a small commission at no extra cost to you. That never decides what's on this page. Everything here is something I've used in production. Full disclosure.