Why this matters
Most identity incidents I see start with something nobody was looking at: an app secret that never expires, a service principal with Directory.ReadWrite.All, an admin with no phishing-resistant MFA, a computer account nobody has touched in two years.
These scripts are the checks I run first on an engagement. They only read and export, they ask for the narrowest Graph scopes that work, and anything that could change your directory stays a -WhatIf dry run until you decide otherwise.