使用Office 365 PowerShell筛选仅启用Exchange Online(Plan2)的E3授权用户
Got it, let's walk through how to generate that exact report you're after—users who have the Office 365 Enterprise E3 license assigned, but only have Exchange Online (Plan 2) turned on from that license suite.
Step 1: Connect to Office 365 PowerShell
First, you need to establish a connection to your tenant's PowerShell environment. If you don't have the Microsoft Graph module installed, start with that, then connect:
# Install the module if you haven't already Install-Module -Name Microsoft.Graph -Force -AllowClobber # Connect to Graph with the required permissions Connect-MgGraph -Scopes User.Read.All, Organization.Read.All, Directory.Read.All
Step 2: Confirm Your E3 License & Service Index
You mentioned that [16] corresponds to the 17th service in the E3 suite (since PowerShell uses zero-based indexing). To double-check this is correct for your tenant, run this command to list all services under the E3 SKU:
# Get the E3 SKU details $e3Sku = Get-MgSubscribedSku | Where-Object { $_.SkuPartNumber -eq "ENTERPRISEPACK" } # List all services with their indices $e3Sku.ServicePlans | ForEach-Object -Begin { $index = 0 } -Process { Write-Host "Index $index : $($_.ServicePlanName) - $($_.ServicePlanId)" $index++ }
Look for the entry named EXCHANGE_S_ENTERPRISE (that's Exchange Online Plan 2) and confirm its index is indeed 16. Adjust the index in the next step if it's different for your tenant.
Step 3: Filter Users & Generate the Report
Now we'll build a script to filter users who meet two criteria:
- They have the E3 license assigned
- Within that E3 license, only the Exchange Online Plan 2 service is enabled (all others are disabled)
Here's the full script:
# Get the E3 SKU $e3Sku = Get-MgSubscribedSku | Where-Object { $_.SkuPartNumber -eq "ENTERPRISEPACK" } # Define the target service index (Exchange Online Plan 2) $targetServiceIndex = 16 # Get all users with E3 license assigned $e3Users = Get-MgUser -All $true -Property Id, DisplayName, UserPrincipalName, AssignedLicenses | Where-Object { $_.AssignedLicenses.SkuId -contains $e3Sku.SkuId } # Filter users where only the target service is enabled in E3 $filteredUsers = $e3Users | ForEach-Object { # Get the specific E3 license assignment for the user $userE3License = $_.AssignedLicenses | Where-Object { $_.SkuId -eq $e3Sku.SkuId } # Check if only the target service is enabled $disabledServiceIndices = $userE3License.DisabledPlans | ForEach-Object { $e3Sku.ServicePlans.IndexOf($e3Sku.ServicePlans | Where-Object { $_.ServicePlanId -eq $_ }) } $allServiceIndices = 0..($e3Sku.ServicePlans.Count - 1) $nonTargetIndices = $allServiceIndices | Where-Object { $_ -ne $targetServiceIndex } $allNonTargetDisabled = $nonTargetIndices | ForEach-Object { $_ -in $disabledServiceIndices } if ($allNonTargetDisabled -notcontains $false) { $_ | Select-Object DisplayName, UserPrincipalName } } # Export the results to a CSV report $filteredUsers | Export-Csv -Path "C:\Temp\E3_OnlyExchangePlan2_Users.csv" -NoTypeInformation -Encoding UTF8 Write-Host "Report generated successfully! Check the CSV file at C:\Temp\E3_OnlyExchangePlan2_Users.csv"
Quick Notes:
- If your tenant uses a different path for reports, adjust the
Export-Csvpath to a location you have access to. - The script verifies that all other services in the E3 suite are disabled—only Exchange Online Plan 2 remains enabled.
- If you hit permission errors, make sure your account has appropriate admin rights (like Global Reader or User Administrator) in your tenant.
内容的提问来源于stack exchange,提问作者jshizzle

