Last active
October 5, 2026 15:43
-
-
Save joerodgers/3774e34e1075128a63a5a372e47e324f to your computer and use it in GitHub Desktop.
Microsoft Graph API calls to list Cost Mgmt. spending policies and user level consumption data.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #requries -modules "Microsoft.Graph.Authentication" | |
| function New-CopilotCostManagementAdminConsentUrl | |
| { | |
| [CmdletBinding()] | |
| param | |
| ( | |
| [Parameter(Mandatory=$true)] | |
| [Guid] | |
| $ClientId, | |
| [Parameter(Mandatory=$true)] | |
| [Guid] | |
| $TenantId, | |
| [Parameter(Mandatory=$false)] | |
| [switch] | |
| $IncludeWritePermissions | |
| ) | |
| begin | |
| { | |
| $readPermissions = @( | |
| 'https://graph.microsoft.com/CopilotCostManagement.Read.All' | |
| 'https://graph.microsoft.com/CopilotCostManagement-Policy.Read.All' | |
| 'https://graph.microsoft.com/CopilotCostManagement-UserData.Read.All' | |
| 'https://graph.microsoft.com/CopilotCostManagement-Assignment.Read.All' | |
| ) | |
| $writePermissions = @( | |
| 'https://graph.microsoft.com/CopilotCostManagement-Policy.ReadWrite.All' | |
| 'https://graph.microsoft.com/CopilotCostManagement-Assignment.ReadWrite.All' | |
| ) | |
| $permissions = $readPermissions | |
| if( $IncludeWritePermissions.IsPresent ) | |
| { | |
| $permissions += $writePermissions | |
| } | |
| $state = [guid]::NewGuid().ToString('N') | |
| } | |
| process | |
| { | |
| $parameters = [ordered]@{ | |
| client_id = $ClientId.ToString() | |
| scope = $permissions -join ' ' | |
| redirect_uri = 'http://localhost' | |
| state = $state | |
| } | |
| $queryString = ($parameters.GetEnumerator() | ForEach-Object { $_.Key + '=' + [uri]::EscapeDataString([string]$_.Value)}) -join '&' | |
| $consentUrl = "https://login.microsoftonline.com/{0}/v2.0/adminconsent?{1}" -f $TenantId, $queryString | |
| return $consentUrl | |
| } | |
| end | |
| { | |
| } | |
| } | |
| function Get-CopilotCostManagementTenantCreditBalance | |
| { | |
| [CmdletBinding()] | |
| param | |
| ( | |
| ) | |
| begin | |
| { | |
| } | |
| process | |
| { | |
| $uri = "https://graph.microsoft.com/beta/copilot/costmanagement/gettenantcreditbalance()" | |
| $response = Invoke-MgGraphRequest -Method GET -Uri $uri -OutputType PSObject | |
| $response.billingMethodBalances | |
| } | |
| end | |
| { | |
| } | |
| } | |
| function Get-CopilotCostManagementSpendingPolicy | |
| { | |
| [CmdletBinding()] | |
| param | |
| ( | |
| ) | |
| begin | |
| { | |
| } | |
| process | |
| { | |
| $uri = "https://graph.microsoft.com/beta/copilot/costmanagement/spendingPolicies" | |
| $response = Invoke-MgGraphRequest -Method GET -Uri $uri -OutputType PSObject | |
| $response.value | |
| } | |
| end | |
| { | |
| } | |
| } | |
| function Get-CopilotCostManagementUserServiceBalance | |
| { | |
| [CmdletBinding()] | |
| param | |
| ( | |
| [Parameter(Mandatory=$true)] | |
| [Guid] | |
| $UserId | |
| ) | |
| begin | |
| { | |
| $response = $null | |
| $uri = "https://graph.microsoft.com/beta/copilot/costmanagement/userBalances/{0}/serviceBalances" -f $UserId | |
| } | |
| process | |
| { | |
| $response = Invoke-MgGraphRequest -Method GET -Uri $uri -OutputType PSObject | |
| $response.value | |
| } | |
| end | |
| { | |
| } | |
| } | |
| Connect-MgGraph -ClientId $env:CDX_CLIENTID ` | |
| -Scopes "CopilotCostManagement.Read.All", "CopilotCostManagement-Policy.Read.All", "CopilotCostManagement-UserData.Read.All", "GroupMember.ReadBasic.All" ` | |
| -TenantId $env:CDX_TENANTID | |
| # permissions are not in Entra portal yet, need to manually have an admin consent to specific perms | |
| # New-CopilotCostManagementAdminConsentUrl -ClientId $env:CDX_CLIENTID -TenantId $env:CDX_TENANTID | Set-Clipboard | |
| # example to retrive credit consumption for all users in a specific security group for all consumption services | |
| $groupMembers = Get-MgGroupMember -GroupId "ca35eade-c9a9-450d-b4f3-8f3a234a174a" -All | |
| $coworkUserBalances = foreach( $groupMember in $groupMembers ) | |
| { | |
| # example serviceId values; workIQ, teamsPhoneAgent, cowork | |
| Get-CopilotCostManagementUserServiceBalance -UserId $groupMember.Id | Where-Object -Property "serviceId" -eq "cowork" | |
| } | |
| $coworkUserBalances |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment