Role Report
Description
This query can be used to draw an report of the Entra ID role memberships for all users.
Query · kql
let TimeFrame = 30d; IdentityInfo | where Timestamp > ago(TimeFrame) | summarize arg_max(TimeGenerated, *) by AccountObjectId | mv-expand AssignedRoles | where isnotempty(AssignedRoles) | summarize TotalRoles = dcount(tostring(AssignedRoles)), MemberOf = make_set(tostring(AssignedRoles), 1000) by AccountObjectId, AccountDisplayName, AccountUPN | extend ReportDate = now() | sort by TotalRoles desc