SharePoint / Guide 1

Getting started

Which shell to use for what, installing the modules, and signing in to SharePoint Online.

SharePoint has three PowerShell "worlds", and most early frustration comes from using the wrong one. Pick the shell by what you're managing.

You want to manage Use Notes
SharePoint Server farm (2010 → Subscription Edition) SharePoint Management Shell Run on a farm server, elevated ("Run as administrator")
SharePoint Online tenant settings, site collections, sharing Microsoft.Online.SharePoint.PowerShell (SPO module) Needs the SharePoint Administrator role
SharePoint Online content: lists, libraries, files, permissions, pages PnP.PowerShell Needs your own Entra ID app registration (see below)
Microsoft 365 Groups, Teams, users Microsoft Graph PowerShell / Teams module Often needed alongside SharePoint work

About the example URLs

All examples in this project use two test environments:

Environment Example URL
SharePoint Server (on-premises) test farm https://sharepoint.ravindran.in
SharePoint Online test tenant https://sharepointonline.ravindran.in
SharePoint Online admin center https://sharepointonline-admin.ravindran.in

Replace them with your own. On a standard Microsoft 365 tenant, SharePoint Online sites live at https://<tenant>.sharepoint.com and the admin center at https://<tenant>-admin.sharepoint.com.

Tip 1 – Install the online modules for your user only

No admin rights needed and no conflicts with other users on the machine:

Install-Module Microsoft.Online.SharePoint.PowerShell -Scope CurrentUser
Install-Module PnP.PowerShell -Scope CurrentUser

Current PnP.PowerShell releases require PowerShell 7 (7.4 or later for version 3.x). The SPO module works best in Windows PowerShell 5.1; if you hit loading errors in PowerShell 7, import it with:

Import-Module Microsoft.Online.SharePoint.PowerShell -UseWindowsPowerShell

Keep them updated: Update-Module PnP.PowerShell

Tip 2 – Register your own Entra ID app for PnP.PowerShell

The shared multi-tenant "PnP Management Shell" app was retired in September 2024. Every tenant now needs its own app registration. PnP can create it for you (you need rights to register apps and grant consent):

Register-PnPEntraIDAppForInteractiveLogin -ApplicationName "PnP PowerShell - SharePoint Admin" `
    -Tenant ravindran.onmicrosoft.com

Note the Client ID it returns, then connect with:

Connect-PnPOnline -Url https://sharepointonline.ravindran.in/sites/HR -ClientId <client-id> -Interactive

All PnP scripts on this site accept -ClientId, or read it from an environment variable so you don't have to type it every time. Add this to your $PROFILE:

$env:PNP_CLIENT_ID = '00000000-0000-0000-0000-000000000000'

Tip 3 – Use certificate auth for scheduled jobs

Interactive login doesn't work for unattended tasks. Use an app registration with a certificate:

Connect-PnPOnline -Url https://sharepointonline.ravindran.in `
    -ClientId <client-id> -Tenant ravindran.onmicrosoft.com -Thumbprint <cert-thumbprint>

Grant the app only the permissions it needs. Sites.Selected lets you give access to specific sites instead of the whole tenant.

Tip 4 – On-premises: give admins shell access properly

"Cannot access the local farm" almost always means the account lacks database rights. From an account that already has access:

Add-SPShellAdmin -UserName RAVINDRAN\sp-admin
# Also grant access to every content database:
Get-SPContentDatabase | ForEach-Object { Add-SPShellAdmin -UserName RAVINDRAN\sp-admin -Database $_ }

Always open the SharePoint Management Shell with "Run as administrator".

Tip 5 – Load SharePoint cmdlets in any PowerShell window

In a plain PowerShell console on a farm server:

Add-PSSnapin Microsoft.SharePoint.PowerShell -ErrorAction SilentlyContinue

The on-premises scripts on this site do this for you.

Tip 6 – Execution policy and downloaded scripts

Set-ExecutionPolicy RemoteSigned -Scope CurrentUser
Get-ChildItem -Path .\scripts -Recurse -Filter *.ps1 | Unblock-File

Tip 7 – Always keep a transcript

It's the cheapest audit trail you'll ever have, and it has saved me in more than one change review.

Start-Transcript -Path "C:\Logs\SP_$(Get-Date -Format yyyyMMdd_HHmm).log"
# ... your work ...
Stop-Transcript

Tip 8 – Read the help before you run

Every script on this site has comment-based help:

Get-Help .\Get-SPLargeLists.ps1 -Examples