Skip to content

Repository files navigation

🛠️ Engineer

PowerShell scripts, administrative tools, and dashboards for IT Administrators, Cloud, Microsoft 365, Azure, Intune, SCCM, AVD, Entra ID, Security, and Automation.

License: Apache 2.0 PowerShell GitHub release (latest by date) GitHub issues GitHub last commit PRs Welcome Maintained by Benson Lam


📖 Project Overview

Engineer is a curated, growing collection of PowerShell scripts, administrative utilities, and dashboards built to solve real, everyday problems faced by IT Administrators and Cloud Engineers working across Microsoft 365, Azure, Microsoft Intune, SCCM (Configuration Manager), Azure Virtual Desktop (AVD), Microsoft Entra ID, and broader enterprise automation and security workflows.

Every tool in this repository is written from hands-on operational experience — the goal is not to publish theoretical scripts, but production-tested, reusable automation that reduces manual effort, improves consistency, and strengthens the security posture of the environments it's used in.

This repository is maintained by Benson Lam, Cloud Technical Lead at cubesys Pty Ltd, and is released under the Apache License 2.0 to encourage community use, contribution, and collaboration — while preserving author attribution and patent protection.


✨ Features

  • 🔹 PowerShell-first — modular, well-commented scripts designed to be read, understood, and safely adapted.
  • 🔹 Microsoft 365 & Entra ID tooling — user lifecycle, licensing, reporting, and hygiene scripts.
  • 🔹 Azure automation — resource management, cost/utilization helpers, and governance scripts.
  • 🔹 Intune & SCCM (Configuration Manager) — device compliance, application deployment, and reporting tools.
  • 🔹 Azure Virtual Desktop (AVD) — session host management and environment health scripts.
  • 🔹 Security & Automation — hardening checks, audit scripts, and scheduled automation helpers.
  • 🔹 Dashboards — lightweight reporting/dashboard tooling for operational visibility.
  • 🔹 Consistent script headers — every script is traceable to its author, license, and version.
  • 🔹 Community-first structure — issue templates, contribution guidelines, and a clear roadmap.

📸 Screenshots

Screenshots and demo GIFs for each tool are stored in /images and linked from each tool's own README where applicable.

Tool Preview
Example Dashboard Dashboard Preview
Example Script Output Script Output Preview

(Add tool-specific screenshots as new tools are published.)


📦 Installation

Option 1 — Clone the repository

git clone https://github.com/Benson-Lam/Engineer.git
cd Engineer

Option 2 — Download a specific release

Download a versioned, tested release from the Releases page rather than the main branch if you want stability.

Option 3 — Download a single script

Each script is self-contained where possible. You can download an individual .ps1 file directly from the relevant /scripts, /tools, or /dashboards subfolder.

Requirements check

Before running any script, review its header block and the Requirements section below for required PowerShell version and modules.


🚀 Usage

  1. Browse the relevant category folder (/scripts, /tools, /dashboards) or use the repository search to find the tool you need.
  2. Open the script and read the header block — it documents purpose, parameters, and prerequisites.
  3. Review the script fully before running it in any production environment (see Disclaimer).
  4. Run with appropriate administrative/Graph/Azure permissions as documented per script, for example:
.\Get-IntuneDeviceComplianceReport.ps1 -TenantId "<tenant-id>" -ExportPath "C:\Reports"
  1. Each tool folder may contain its own README.md with tool-specific usage instructions, parameters, and examples.

🧰 Requirements

  • PowerShell 5.1 (Windows PowerShell) or PowerShell 7+ (cross-platform), as specified per script.
  • Relevant Microsoft modules, depending on the tool, which may include:
    • Microsoft.Graph / Microsoft.Graph.Intune
    • Az / Az.Accounts / Az.Resources
    • ExchangeOnlineManagement
    • Microsoft.Online.SharePoint.PowerShell
    • SCCM/ConfigMgr console PowerShell module (ConfigurationManager.psd1)
  • Appropriate role-based access (e.g., Intune Administrator, Global Reader, Azure RBAC roles) as documented per script.
  • Network access to the relevant Microsoft 365 / Azure endpoints.

Individual scripts will list their exact dependencies in the script header and/or an accompanying README.md.


🤝 Contributing

Contributions, suggestions, and improvements are welcome and genuinely encouraged — this project grows through community input.

Please read CONTRIBUTING.md before submitting a pull request. In short:

  • Fork the repository and create a feature branch.
  • Follow the existing script header and folder conventions.
  • Test your script/tool before submitting.
  • Open a pull request using the provided PR template.

All contributions are accepted under the terms of the Apache License 2.0.


💬 Support

  • 🐛 Found a bug? Open a Bug Report.
  • 💡 Have an idea? Open a Feature Request.
  • 💭 General questions or ideas? Use GitHub Discussions (if enabled) for open-ended conversation.
  • 🔒 Security concern? Please follow the process in SECURITY.md — do not open a public issue for vulnerabilities.

🗺️ Roadmap

  • Expand Intune device compliance & reporting scripts.
  • Add Entra ID conditional access audit and reporting tools.
  • Add SCCM/ConfigMgr application deployment health-check scripts.
  • Build a lightweight web-based dashboard for aggregated reporting.
  • Add Pester-based automated testing for core scripts.
  • Publish contribution "good first issue" labels to encourage community involvement.
  • Expand AVD session host and FSLogix diagnostic tooling.

See the Issues board for the live, up-to-date roadmap and progress.


🔖 Versioning

This project follows Semantic Versioning (SemVer) — MAJOR.MINOR.PATCH:

  • MAJOR — breaking changes to script parameters/behaviour.
  • MINOR — new tools/scripts or backward-compatible functionality.
  • PATCH — bug fixes and non-breaking improvements.

See CHANGELOG.md for a full history of changes, and /releases / the GitHub Releases page for packaged versions.


⚖️ License

This project is licensed under the Apache License, Version 2.0 — see LICENSE for full details.

You are free to use, modify, and redistribute this software (including commercially), provided that you retain the original copyright notice, license text, and attribution notices as required by the Apache 2.0 license. See the NOTICE file for attribution requirements.

⚠️ Also see the Disclaimer below regarding use in production environments.


⚠️ Disclaimer

The scripts and tools in this repository interact with administrative and production systems, including Microsoft 365, Azure, Intune, SCCM, AVD, and Entra ID. They are provided "AS IS", without warranty of any kind.

  • Always review and test scripts in a non-production environment first.
  • You are responsible for validating that a script is appropriate for your environment before running it.
  • The author and contributors accept no liability for data loss, downtime, misconfiguration, or any other damage resulting from the use of these tools.
  • Some scripts may require highly privileged access (e.g., Global Administrator, Intune Administrator). Apply the principle of least privilege wherever possible.

See the full DISCLAIMER.md for complete terms.


👤 Author

Benson Lam Cloud Technical Lead @ cubesys Pty Ltd

If this project has helped you, please consider ⭐ starring the repository — it helps others discover the project and supports continued development.


Copyright © 2026 Benson Lam — Released under the Apache License 2.0

About

**Engineer** — A curated collection of PowerShell scripts and admin tools for Microsoft 365, Azure, Intune, SCCM, AVD, and Entra ID. Built by a Cloud Technical Lead for real-world IT automation, security, and reporting. Apache 2.0 licensed — free for personal and commercial use.

Topics

Resources

Code of conduct

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages