Repository navigation
Expand file tree
/
Copy pathPowerShell-Graph-GetMailboxOof.ps1
More file actions
163 lines (144 loc) · 5.25 KB
/
Copy pathPowerShell-Graph-GetMailboxOof.ps1
File metadata and controls
163 lines (144 loc) · 5.25 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
# PowerShell-Graph-GetMailboxOof.ps1
# =====================================================================
# Raw Microsoft Graph REST sample
# Read OOF / automatic replies from a mailbox using APPLICATION OAuth
#
# IMPORTANT PERMISSIONS (Application permissions on the app registration):
#
# - MailboxSettings.Read
# Least-privileged application permission required to READ
# mailbox settings, including automaticRepliesSetting / OOF.
#
# - MailboxSettings.ReadWrite
# NOT needed for this script.
# Only required if you want to MODIFY mailbox settings.
#
# IMPORTANT CONSENT NOTE:
# - Application permissions require admin consent in Entra ID.
# - If the permission is missing or admin consent was not granted,
# Graph will typically return 403 Forbidden.
#
# IMPORTANT AUTH NOTE:
# - This script uses client credentials flow (app-only).
# - The client secret is hard-coded ONLY because requested.
# - Do not do this in production.
# =====================================================================
# ----------------------------
# Hard-coded app credentials
# ----------------------------
$tenantId = "YOUR_TENANT_ID_GUID"
$clientId = "YOUR_APP_REG_CLIENT_ID_GUID"
$clientSecret = "YOUR_CLIENT_SECRET"
# ----------------------------
# Mailbox to read OOF from
# Can be UPN or user object id
# Example:
# user@contoso.com
# ----------------------------
$targetMailbox = "user@contoso.com"
# ----------------------------
# Token endpoint
# ----------------------------
$tokenUri = "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token"
# ----------------------------
# Acquire app-only token
# scope=.default means "use the application permissions
# already granted to this app for Microsoft Graph"
# ----------------------------
$tokenBody = @{
client_id = $clientId
client_secret = $clientSecret
scope = "https://graph.microsoft.com/.default"
grant_type = "client_credentials"
}
try {
Write-Host "Requesting application OAuth token..." -ForegroundColor Cyan
$tokenResponse = Invoke-RestMethod `
-Method POST `
-Uri $tokenUri `
-ContentType "application/x-www-form-urlencoded" `
-Body $tokenBody `
-ErrorAction Stop
if (-not $tokenResponse.access_token) {
throw "No access_token returned from token endpoint."
}
$accessToken = $tokenResponse.access_token
Write-Host "Token acquired." -ForegroundColor Green
}
catch {
Write-Host "Failed to acquire token." -ForegroundColor Red
Write-Host $_.Exception.Message -ForegroundColor Red
return
}
# ----------------------------
# Graph endpoint for OOF
# GET /users/{id|userPrincipalName}/mailboxSettings/automaticRepliesSetting
# ----------------------------
$encodedMailbox = [System.Uri]::EscapeDataString($targetMailbox)
$graphUri = "https://graph.microsoft.com/v1.0/users/$encodedMailbox/mailboxSettings/automaticRepliesSetting"
# ----------------------------
# Graph headers
# ----------------------------
$headers = @{
Authorization = "Bearer $accessToken"
Accept = "application/json"
"client-request-id" = [guid]::NewGuid().ToString()
}
try {
Write-Host "Calling Graph to read OOF settings for $targetMailbox ..." -ForegroundColor Cyan
$oof = Invoke-RestMethod `
-Method GET `
-Uri $graphUri `
-Headers $headers `
-ErrorAction Stop
Write-Host ""
Write-Host "================ OOF / Automatic Replies ================" -ForegroundColor Yellow
Write-Host ("Mailbox : {0}" -f $targetMailbox)
Write-Host ("Status : {0}" -f $oof.status)
Write-Host ("ExternalAudience : {0}" -f $oof.externalAudience)
if ($oof.scheduledStartDateTime) {
Write-Host ("Scheduled Start : {0} ({1})" -f `
$oof.scheduledStartDateTime.dateTime,
$oof.scheduledStartDateTime.timeZone)
}
else {
Write-Host "Scheduled Start : "
}
if ($oof.scheduledEndDateTime) {
Write-Host ("Scheduled End : {0} ({1})" -f `
$oof.scheduledEndDateTime.dateTime,
$oof.scheduledEndDateTime.timeZone)
}
else {
Write-Host "Scheduled End : "
}
Write-Host ""
Write-Host "Internal Reply Message:"
Write-Host "--------------------------------------------------------"
Write-Host $oof.internalReplyMessage
Write-Host ""
Write-Host "External Reply Message:"
Write-Host "--------------------------------------------------------"
Write-Host $oof.externalReplyMessage
Write-Host ""
}
catch {
Write-Host "Graph call failed." -ForegroundColor Red
# Try to surface useful REST details if present
if ($_.Exception.Response -ne $null) {
try {
$reader = New-Object System.IO.StreamReader($_.Exception.Response.GetResponseStream())
$reader.BaseStream.Position = 0
$reader.DiscardBufferedData()
$responseBody = $reader.ReadToEnd()
Write-Host "Response body:" -ForegroundColor Red
Write-Host $responseBody -ForegroundColor Red
}
catch {
Write-Host $_.Exception.Message -ForegroundColor Red
}
}
else {
Write-Host $_.Exception.Message -ForegroundColor Red
}
}