โ† Back to catalog
Cloud & Identity

TENDRIL

Entra ID group dependency audit.

Answers "what breaks if we delete this group?" Traces a group's blast radius across group-based licensing, Conditional Access, enterprise apps, directory roles, nested membership, administrative units, Intune, SharePoint, Exchange, and Azure RBAC. Optional deep scans (-IncludeSharePoint / -IncludeExchange / -IncludeAzureRbac) extend coverage.

Quick Launch

Run TENDRIL

Run in an elevated PowerShell window. Downloads tendril.ps1 from CursedTechnocrat/TechnicianToolkit and executes it.

Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\tendril.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/tendril.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f
Category
Cloud & Identity
Identifier
TENDRIL
Tags
groups, entra, dependencies