SharePoint / Guide 1
Getting started
Which shell to use for what, installing the modules, and signing in to SharePoint Online.
SharePoint has three PowerShell "worlds", and most early frustration comes from using the wrong one. Pick the shell by what you're managing.
| You want to manage | Use | Notes |
|---|---|---|
| SharePoint Server farm (2010 → Subscription Edition) | SharePoint Management Shell | Run on a farm server, elevated ("Run as administrator") |
| SharePoint Online tenant settings, site collections, sharing | Microsoft.Online.SharePoint.PowerShell (SPO module) |
Needs the SharePoint Administrator role |
| SharePoint Online content: lists, libraries, files, permissions, pages | PnP.PowerShell |
Needs your own Entra ID app registration (see below) |
| Microsoft 365 Groups, Teams, users | Microsoft Graph PowerShell / Teams module | Often needed alongside SharePoint work |
About the example URLs
All examples in this project use two test environments:
| Environment | Example URL |
|---|---|
| SharePoint Server (on-premises) test farm | https://sharepoint.ravindran.in |
| SharePoint Online test tenant | https://sharepointonline.ravindran.in |
| SharePoint Online admin center | https://sharepointonline-admin.ravindran.in |
Replace them with your own. On a standard Microsoft 365 tenant, SharePoint Online sites live at https://<tenant>.sharepoint.com and the admin center at https://<tenant>-admin.sharepoint.com.
Tip 1 – Install the online modules for your user only
No admin rights needed and no conflicts with other users on the machine:
Install-Module Microsoft.Online.SharePoint.PowerShell -Scope CurrentUser
Install-Module PnP.PowerShell -Scope CurrentUser
Current PnP.PowerShell releases require PowerShell 7 (7.4 or later for version 3.x). The SPO module works best in Windows PowerShell 5.1; if you hit loading errors in PowerShell 7, import it with:
Import-Module Microsoft.Online.SharePoint.PowerShell -UseWindowsPowerShell
Keep them updated: Update-Module PnP.PowerShell
Tip 2 – Register your own Entra ID app for PnP.PowerShell
The shared multi-tenant "PnP Management Shell" app was retired in September 2024. Every tenant now needs its own app registration. PnP can create it for you (you need rights to register apps and grant consent):
Register-PnPEntraIDAppForInteractiveLogin -ApplicationName "PnP PowerShell - SharePoint Admin" `
-Tenant ravindran.onmicrosoft.com
Note the Client ID it returns, then connect with:
Connect-PnPOnline -Url https://sharepointonline.ravindran.in/sites/HR -ClientId <client-id> -Interactive
All PnP scripts on this site accept -ClientId, or read it from an environment variable so you don't have to type it every time. Add this to your $PROFILE:
$env:PNP_CLIENT_ID = '00000000-0000-0000-0000-000000000000'
Tip 3 – Use certificate auth for scheduled jobs
Interactive login doesn't work for unattended tasks. Use an app registration with a certificate:
Connect-PnPOnline -Url https://sharepointonline.ravindran.in `
-ClientId <client-id> -Tenant ravindran.onmicrosoft.com -Thumbprint <cert-thumbprint>
Grant the app only the permissions it needs. Sites.Selected lets you give access to specific sites instead of the whole tenant.
Tip 4 – On-premises: give admins shell access properly
"Cannot access the local farm" almost always means the account lacks database rights. From an account that already has access:
Add-SPShellAdmin -UserName RAVINDRAN\sp-admin
# Also grant access to every content database:
Get-SPContentDatabase | ForEach-Object { Add-SPShellAdmin -UserName RAVINDRAN\sp-admin -Database $_ }
Always open the SharePoint Management Shell with "Run as administrator".
Tip 5 – Load SharePoint cmdlets in any PowerShell window
In a plain PowerShell console on a farm server:
Add-PSSnapin Microsoft.SharePoint.PowerShell -ErrorAction SilentlyContinue
The on-premises scripts on this site do this for you.
Tip 6 – Execution policy and downloaded scripts
Set-ExecutionPolicy RemoteSigned -Scope CurrentUser
Get-ChildItem -Path .\scripts -Recurse -Filter *.ps1 | Unblock-File
Tip 7 – Always keep a transcript
It's the cheapest audit trail you'll ever have, and it has saved me in more than one change review.
Start-Transcript -Path "C:\Logs\SP_$(Get-Date -Format yyyyMMdd_HHmm).log"
# ... your work ...
Stop-Transcript
Tip 8 – Read the help before you run
Every script on this site has comment-based help:
Get-Help .\Get-SPLargeLists.ps1 -Examples