Usage Guide
Basic Usage
Import-Module ./AzureScout.psd1
Invoke-AzureScoutWith no parameters, AZSC runs a full ARM-only inventory (-Scope ArmOnly is the default — Entra ID is skipped unless you pass -Scope All or -Scope EntraOnly) using your current Azure context. It produces the React report and machine-readable JSON outputs selected by the global output contract.
Scope
The -Scope parameter controls which data domains are inventoried:
| Value | Behavior |
|---|---|
ArmOnly (default) | Inventories ARM resources only — Entra ID is not scanned unless requested |
EntraOnly | Skips all ARM extraction — Entra ID objects only |
All | Inventories both ARM resources and Entra ID objects |
# Default — ARM only, Entra ID is skipped
Invoke-AzureScout
# ARM + Entra ID
Invoke-AzureScout -Scope All
# Entra ID only — skip ARM resources
Invoke-AzureScout -Scope EntraOnlyTIP
This is the -Scope default for inventory mode only. In assessment mode (-Assessment) the same -Scope parameter defaults to All and has different semantics — see Assessment mode: -Scope.
Output Format
The -OutputFormat parameter has the same live values for inventory, assessment, and combined runs:
| Value | Produces |
|---|---|
All (default) | React, Json, and JsonEvidence |
React | Self-contained report-react.html with an Inventory & audit page; assessment sections appear when assessments run |
Json | Machine-readable run results |
JsonEvidence | Resources-only evidence export |
# Machine-readable results only
Invoke-AzureScout -OutputFormat Json
# Self-contained inventory report
Invoke-AzureScout -OutputFormat ReactLegacy values such as Excel, Markdown, AsciiDoc, PowerBI, Html, Pptx, Pdf, Word, EChartsDashboard, and GovernanceReport are on hold. They are not live inventory alternatives. Use the export menu inside the React report for Markdown, JSON, CSV, PDF/Print, and standalone HTML.
Report Location
Every run writes to its own folder, so a rerun never overwrites the previous one:
- Windows:
C:\AzureScout\<timestamp>_<tenant>\ - Linux/macOS:
$HOME/AzureScout/<timestamp>_<tenant>/
Override the base path with -ReportDir, name the run folder with -RunName, or skip the run folder entirely with -Force:
# Different base path
Invoke-AzureScout -ReportDir 'D:\Reports'
# Friendly run folder name instead of the timestamp
Invoke-AzureScout -RunName 'Production-TenantA'
# Write straight into the base path, overwriting in place
Invoke-AzureScout -ReportDir 'D:\Reports' -ForceFull detail, including pruning old runs with Clear-AZSCCacheFolder -OlderThan, is in Output Files & Formats.
Every run retains its complete evidence set: raw-inventory.json (everything the Resource Graph pass collected, before any manifest filtered it down), ReportCache/Discovery.json (one completeness record per resource plus generic ARM relationships), collector-rowcounts.json, collection-health.json, and the complete ReportCache/DiagramCache trees. See Output Files & Formats — evidence artifacts. Discovery/report payloads preserve sensitive field presence but replace credential values with [REDACTED].
Enterprise tenant runs (direct account access)
Use -AllAccessibleTenants when the signed-in user is already a member or guest with access in several Entra tenants. Azure Scout enumerates those tenants, runs the existing pipeline once per tenant, and contains an authentication or permission failure to that tenant. This path does not use Azure Lighthouse.
# Every tenant visible to the signed-in account
Invoke-AzureScout -AllAccessibleTenants -Scope All -RunName 'Enterprise-Portfolio'
# Only a selected subset
Invoke-AzureScout -TenantID '<tenant-a>','<tenant-b>' -Scope All -RunName 'Selected-Tenants'A multi-tenant run creates one umbrella folder. Its root report-react.html (also copied as index.html) records what was selected, what was skipped, each tenant outcome, resource and subscription counts, and links to each detailed tenant report. run-summary.json exposes the same status for automation.
The automatic enumeration switch is deliberately explicit: a bare Invoke-AzureScout remains a single-tenant run and cannot unexpectedly launch scans across every tenant the account can reach.
Content Toggles
Switch parameters to include/exclude specific content:
| Parameter | Effect |
|---|---|
-SecurityCenter | Include Microsoft Defender for Cloud findings |
-IncludeTags | Include resource tags in reports |
-IncludeDevOps | Include Azure DevOps projects, pipelines, service connections, repositories, and agent pools |
-IncludeOkta | Include the separate Okta control plane; also requires an HTTPS -OktaOrganizationUrl and SecureString -OktaApiToken |
-IncludeOnPremisesIdentity | Include local Entra Connect and AD topology from a host with the required read-only modules |
-SkipAdvisory | Skip Azure Advisor recommendations |
-SkipPolicy | Skip Azure Policy compliance data |
-SkipPermissionCheck | Skip the pre-flight permission validation |
Okta is explicitly opt-in. Supply its token without placing plaintext in shell history:
$oktaToken = Read-Host 'Okta read-only API token' -AsSecureString
Invoke-AzureScout -Scope All -IncludeOkta `
-OktaOrganizationUrl 'https://example.okta.com' -OktaApiToken $oktaTokenFor Entra Connect/AD topology, run on a host that can read those local services and modules:
Invoke-AzureScout -Scope All -IncludeOnPremisesIdentityUnavailable local modules and denied Okta endpoints are recorded as coverage gaps; they are not reported as proof that the corresponding configuration is absent.
Azure DevOps
-IncludeDevOps adds five worksheets covering your Azure DevOps estate. It reuses the current Azure sign-in, so no personal access token is needed in the common case:
# Organizations discovered from the signed-in profile
Invoke-AzureScout -TenantID '00000000-...' -IncludeDevOps
# Name them explicitly (required for service principals)
Invoke-AzureScout -TenantID '00000000-...' -IncludeDevOps -DevOpsOrganization 'contoso','fabrikam'See Azure DevOps for the service-connection-to-subscription cross-reference and the full permission model.
Subscription & Management Group Filters
# Specific subscriptions only
Invoke-AzureScout -SubscriptionID 'sub-001','sub-002'
# Management group scoped
Invoke-AzureScout -ManagementGroup 'mg-prod'Naming the Report
Invoke-AzureScout -ReportName 'Q4-2025-Audit'JSON Output Structure
The JSON report uses a normalized, flat resource schema:
{
"metadata": {
"tenantId": "...",
"generatedAt": "2026-01-15T10:30:00Z",
"scope": "All",
"moduleVersion": "1.5.0"
},
"resources": [
{
"id": "/subscriptions/.../resourceGroups/.../providers/...",
"name": "my-vm",
"TYPE": "microsoft.compute/virtualmachines",
"resourceGroup": "rg-prod",
"subscriptionId": "...",
"location": "eastus",
"properties": { }
}
]
}