Skip to main content
PowerShell 5.1 / 7Hybrid AD + M365v1.0

Beyond Automation script pack

Stop doing offboarding by hand.

OffboardPilot automates the complete hybrid AD + M365 offboarding workflow in a single guided PowerShell script — six steps, a color-coded reconciliation report, and a full session transcript logged automatically.

✓ Full commented source — no obfuscation✓ No hardcoded values✓ Works in any hybrid environment
Invoke-UserOffboard.ps1v1.0
# ── OffboardPilot v1.0 ──────────────────
PS> .\Invoke-UserOffboard.ps1
Enter UPN to offboard:
[✓] EXO identity DN captured
── STEP 1 · AD ACCOUNT ─────────────────
[✓] AD account disabled
── STEP 2 · ENTRA ID ───────────────────
[✓] Sign-in blocked
[✓] Sessions + tokens revoked
── STEP 4 · MAILBOX ────────────────────
[✓] Converted to Shared mailbox
[✓] Forwarding → [email protected]
[✓] 3 licenses removed
OFFBOARD COMPLETE — 6/6 steps passed
Transcript → C:\Scripts\Logs\
6automated steps
3included scripts
1audit trail per run
0hardcoded values

The silent failure

Most offboarding scripts get the EXO groups wrong.

When you remove a user’s M365 license, Exchange Online quietly reverts their primary email address back to [email protected]. Any script that filters distribution group memberships by email address — and most do — runs after the license removal, hits the wrong address, finds nothing, and reports success.

The user is still in every cloud DL they were ever added to.

OffboardPilot captures the user’s Exchange Distinguished Name before any license changes, then uses that DN for every group query. DN is stable regardless of licensing state.

What it does

Six steps. One script. Nothing missed.

01

Disable AD account

Disables the on-premises Active Directory account immediately.

02

Block Entra ID sign-in

Sets BlockSignIn in Entra ID / Azure AD to prevent cloud authentication.

03

Revoke M365 sessions

Revokes all active Microsoft 365 sessions and OAuth refresh tokens.

04

Mailbox conversion

Converts to Shared mailbox, configures forwarding, and removes all assigned licenses.

05

Remove EXO groups

Removes cloud-only Exchange Online distribution group memberships using the stable DN.

06

Remove AD groups

Removes on-premises AD group memberships including AD-synced distribution lists.

Built for real hybrid environments

Works out of the box. No configuration required.

  • ✓ No hardcoded values — drop it in any environment
  • ✓ Handles users with no EXO mailbox — EXO steps skip gracefully, AD steps continue
  • ✓ Mailbox size pre-check — warns before conversion if mailbox exceeds 50GB
  • ✓ EXO group membership uses Distinguished Name — prevents silent misses after license removal
  • ✓ AD operations use explicit admin credentials — supports least-privilege accounts
  • ✓ Required modules auto-install on first run
  • ✓ Full session transcript logged automatically to C:\Scripts\Logs\

Requirements

  • PowerShell 5.1 (recommended) — PS7 compatible
  • RSAT Active Directory module
  • ExchangeOnlineManagement module
  • Microsoft.Graph.Authentication module
  • Domain-connected Windows workstation