Skip to main content

Authentication

Before you can use the other cmdlets, connect to Microsoft Graph with Connect-Windows365. It supports five authentication methods.

MethodExampleBest for
InteractiveConnect-Windows365Admins working at their own machine
Device codeConnect-Windows365 -DeviceCodeRemote shells and machines without a browser
Client secretConnect-Windows365 -TenantID contoso.onmicrosoft.com -ClientID <app-id> -ClientSecret <secret>Automation and scheduled jobs
Client certificateConnect-Windows365 -TenantID contoso.onmicrosoft.com -ClientID <app-id> -ClientCertificate $certAutomation without storing secrets
Access tokenConnect-Windows365 -Token $accessTokenReusing a token from another tool or pipeline

Interactive and device code sign-in use delegated permissions; the client secret and certificate methods use application permissions on your own app registration. See Permissions for the list.

Interactive​

Opens a browser window to sign in with your own account. The tenant is determined by the account you sign in with, so no tenant parameter is needed.

Connect-Windows365

Device code​

Use this in remote sessions, containers or other environments without a browser. You get a code to enter at https://microsoft.com/devicelogin on any device.

Connect-Windows365 -DeviceCode

Client secret​

Use an app registration (service principal) with a client secret for unattended automation.

Connect-Windows365 -TenantID contoso.onmicrosoft.com -ClientID <app-id> -ClientSecret <secret>
warning

Avoid hard-coding secrets in scripts. Load them from a secure source such as Azure Key Vault or the Microsoft.PowerShell.SecretManagement module.

Client certificate​

Certificate authentication avoids storing a secret. Pass an X509Certificate2 object that includes the private key, not just the thumbprint:

$cert = Get-Item "Cert:\CurrentUser\My\<THUMBPRINT>"
Connect-Windows365 -TenantID contoso.onmicrosoft.com -ClientID <app-id> -ClientCertificate $cert

On macOS or Linux, load the certificate from a PFX file instead:

$cert = [System.Security.Cryptography.X509Certificates.X509Certificate2]::new("./app.pfx", $pfxPassword)
Connect-Windows365 -TenantID contoso.onmicrosoft.com -ClientID <app-id> -ClientCertificate $cert

Access token​

Already have a Microsoft Graph access token, for example from another tool or a pipeline? Pass it directly. The token must be valid for Microsoft Graph and include the Cloud PC permissions.

Connect-Windows365 -Token $accessToken

Disconnect​

Disconnect-Windows365

This signs out and clears the token cache.