Note
The bundled pac-admin-query agent skill was written by Andrew Petrochuk. Thanks, Andrew!
Version 2.9.3 of the Power Platform CLI added a new command, pac admin query, for querying your tenant-wide Power Platform inventory. This repo gives you working sample queries for it, and it bundles an agent skill by Andrew Petrochuk so GitHub Copilot can build and run them for you.
The skill lives in .github/skills/pac-admin-query/ and bundles a SKILL.md reference plus ready-to-adapt example query files.
- A PAC CLI build that includes
pac admin query(verified with2.9.3). - An active PAC auth profile with tenant context and permission to call the Power Platform inventory API.
pac auth list # inspect profiles
pac auth select # activate the right oneTip
Prefer a query file over inline JSON to avoid shell-escaping headaches.
| Argument | Alias | Description |
|---|---|---|
--query-file |
-qf |
Read the query body from a .json file. |
--query |
-q |
Provide the query body inline as a string. |
--output-type |
-ot |
Grid (default), List, or Json. |
--output-file |
-of |
Write results to a file (Grid CSV, Json JSON). |
| Output type | Flag | Best for |
|---|---|---|
Grid (default) |
-ot Grid |
Quick, readable tables |
List |
-ot List |
Simple line-per-field text |
Json |
-ot Json |
Nested data, metadata & pagination |
Run a query file and print a Grid table to the console (the default output type):
pac admin query --query-file .\query.jsonThe -qf alias does the same thing:
pac admin query -qf .\query.jsonGet the full JSON response, with metadata, nested props, and the pagination token:
pac admin query -qf .\query.json -ot JsonPrint simple line-per-field List output:
pac admin query -qf .\query.json -ot ListExport a CSV file (Grid plus --output-file):
pac admin query -qf .\query.json -ot Grid -of .\inventory.csvExport the raw JSON response to a file:
pac admin query -qf .\query.json -ot Json -of .\inventory.jsonWarning
There's also an inline --query / -q flag, but shell quoting around the JSON (especially the $type keys) frequently trips it up. Stick with --query-file: save the JSON to a .json file and point -qf at it.
pac auth list # see profiles
pac auth select --index 1 # activate one
pac auth who # confirm the active profile & tenantGrid/List cap what they print. For big exports, use Json and follow the skipToken: when the response has a non-empty skipToken, copy it into Options.SkipToken in your query file and rerun to fetch the next page, keeping every other clause unchanged.
See SKILL.md for the full request shape, clause reference, and resource-type table.
Every query below has its own folder under samples/ with a runnable query.json, a sanitized output captured from a live tenant, and a short write-up. Open a sample to see the full query and results.
Important
The inventory API exposes resource structure (owner, environment, connectors, created and modified dates), not run or launch telemetry or Entra account status. So treat "stale" as not recently modified rather than unused, and confirm "orphaned" ownership separately.
| Sample | What it answers |
|---|---|
| Environment inventory | Every environment with region, type, and managed state. |
| Environment sprawl | How many resources of each type live in each environment? |
| Managed environments | How many environments are managed versus not? |
| Environment types | How do environments split across production, sandbox, and developer? |
| Environments by region | Where does your environment data live? |
| Sample | What it answers |
|---|---|
| Count by type | How many resources of each type and location exist? |
| Maker adoption | Who builds the most apps, flows, and agents? |
| New resources | What was created in the last 30 days? |
| Adoption trend | How many resources are created each month? |
| Recently modified | What changed in the last 7 days? |
| Orphaned resources | Which owners should you cross-check against deleted accounts? |
| Sample | What it answers |
|---|---|
| Connector audit | Which connectors are used most across the tenant? |
| Stale connectors | Which connectors are only referenced by dormant resources? |
| Connectors per environment | Which connectors are used in each environment, and how often? |
| Sample | What it answers |
|---|---|
| Recently used | What was used recently, from real usage telemetry? |
| Unused resources | What hasn't been used in 30+ days? |
{ "TableName": "PowerPlatformResources", "Clauses": [ /* ... */ ], "Options": { "Top": 1000, "Skip": 0, "SkipToken": "<paste skipToken here>" } }