ehrnst / querySql.ps1
Created November 26, 2021 12:52
Query Azure SQL server using PowerShell and access token
## This will use your Azure access token and establish a connection to your Azure SQL instance.
## useful when testing network connections or similar
$token = Get-AzAccessToken -Resource ""
# connect to database
$dbConn = New-Object System.Data.SqlClient.SqlConnection
$dbConn.ConnectionString = ",1433;Initial Catalog=myDB;Persist Security Info=False;MultipleActiveResultSets=False;Encrypt=True;TrustServerCertificate=False;"
ehrnst / postgres-policy.json
Created November 29, 2021 08:23
Postgres Azure policy for geo replication with tag override
"properties": {
"displayName": "PostgreSQL should have Geo replication enabled",
"policyType": "Custom",
"mode": "Indexed",
"description": "This policy checks wheter Geo replication is enabled or not. You can exclude the database from the policy by adding 'noGeo' : 'true' as tag and value",
"metadata": {
"category": "SQL",
"createdBy": "75e5f040-6c35-4bc7-baef-eae05fc48acb",
"createdOn": "2021-03-22T12:10:49.814614Z",
ehrnst / azcopy-move.ps1
Created January 25, 2022 15:03
AzCopy to move files in directory structure in Azure blob storage
## connect to storage using SAS
$storageName = ""
$sasToken = ""
$container = ""
$ctx = New-AzureStorageContext -StorageAccountName $storageName -SasToken $sasToken
# get all the blobs
$blobs = Get-AzureStorageBlob -Container $container -Context $ctx
ehrnst / diff.ps1
Created February 7, 2022 09:00
azure pipeline with bicep files push to acr. uses git diff to only push modified modules
$version = get-date -Format yyyy-MM-dd
# get the latest files changed
$files = $(git diff HEAD HEAD~ --name-only -- *.bicep modules/)
if ($files.count -ge 1) {
# copy files to staging
# set a variable and build number
ehrnst / get-resource-changes-from-rg-with-tag.kql
Created March 14, 2022 14:19
Azure resource graph resource changes
// get latest resource changes based on resource group tag
| join kind= inner (
| where type =~ 'microsoft.resources/subscriptions/resourcegroups'
| where isnotempty(tags)
| where tags['key'] =~ 'value'
| project subscriptionId, resourceGroup)
on subscriptionId, resourceGroup
| extend changeTime = todatetime(properties.changeAttributes.timestamp),
ehrnst / containertest.bicep
Created June 16, 2022 07:02
bicep alter params to sub modules
param storageAccountName string
resource container 'Microsoft.Storage/storageAccounts/blobServices/containers@2021-09-01' = {
name: '${storageAccountName}/default/mycontainer'
ehrnst / create-adappgithub.ps1
Created August 24, 2022 11:58
Adding Azure AD and github federated credentials
# creates an appregistration in Azure AD and connects it with a github repo
# use as an example only
param (
ehrnst / azopenai-slack.ps1
Last active April 24, 2023 12:36
Azure OpenAI Slack summary using PowerShell
# slack test
$slackKey = Get-AzKeyVaultsecret -VaultName "" -Name "" -AsPlainText
$azOpenAiKey = Get-AzKeyVaultsecret -VaultName "" -Name "" -AsPlainText
$slackChannelId = ""
$slackThreadId = ""
$openAiUrl = ""
$slackUrl = "$slackChannelId&ts=$slackThreadId&pretty=1"
$slackHeaders= @{
"Authorization" = "Bearer $slackKey"
ehrnst / appRegistrationSignIns.ps1
Last active February 7, 2024 12:37
Get sign in information for app registrations and service principals through EntraID/Log Analytics
This script retrieves Azure Active Directory (AD) applications with expired secrets and checks their sign-in logs.
The script first retrieves all Azure AD applications using the Get-AzADApplication cmdlet. It then filters these applications to only include those where the password credential has expired more than 30 days ago and where there is only one password credential.
For each of these applications, the script retrieves the AppId and constructs three queries to check the sign-in logs for the last 30 days. The queries are for service principal sign-ins, non-interactive user sign-ins, and interactive sign-ins.
The script then executes these queries using the Invoke-AzOperationalInsightsQuery cmdlet and stores the results in three separate variables: $servicePrincipalSignins, $nonInteractiveSignins, and $interactiveSignins.
Finally, the script outputs the results of these queries.
ehrnst / migrate-devops-repo.ps1
Created February 16, 2024 10:57
PowerShell script using GH CLI to migrate Azure DevOps repositories to GitHub
[Parameter(HelpMessage="The Azure DevOps organization.")]
[string]$adoOrg = "Adatum",
[Parameter(Mandatory=$true, HelpMessage="The Azure DevOps team project.")]
[Parameter(Mandatory=$true, HelpMessage="The Azure DevOps repository.")]