Export advanced Entra ID configurations including PIM, MFA, conditional access, and named locations.
Related topics
entra id
azure ad
pim export
conditional access
mfa
identity governance
About this tool
The Entra ID Advanced Export tool captures sophisticated identity configurations not covered by standard tools. Export Privileged Identity Management (PIM) role assignments, conditional access policies, MFA settings, B2B collaboration settings, and named locations.
Using the Graph Beta API, this tool accesses cutting-edge Entra ID features essential for security-focused organizations. Document your zero-trust architecture and identity security posture.
Critical for security audits, compliance assessments, and organizations implementing advanced identity governance.
Key features
Export PIM role assignments
Conditional Access policies
MFA registration status
Named locations configuration
B2B collaboration settings
Cross-tenant access policies
Authentication methods
Identity governance settings
Use cases
Security documentation. Document identity security configuration for audits
Compliance assessment. Verify identity controls against security frameworks
Environment replication. Document settings for dev/test environment setup
Requires a paid edition (config). The Suite bundle includes this tool alongside every other capability in the catalogue.
Limitations & out-of-scope
Runs against the Graph Beta endpoint (not v1.0) to reach PIM, MFA, and named-locations data that GA Graph doesn't expose yet — beta endpoints can change shape or disappear on Microsoft's own schedule without the usual deprecation notice. RoleManagement.Read.All and Policy.Read.All are read-only, so PIM roles can be inventoried but never activated, deactivated, or reassigned from here. IdentityRiskEvent.Read.All returns meaningful data only on tenants licensed for Entra ID P2 — without it, that section of the export is empty by Microsoft's own licensing gate, not a bug in this tool.