Skip to main content
Two scan modules capture Microsoft’s cloud environment, plus a linking type with no scan of its own. Both scan modules need an app registration for access — see Inventorying Microsoft 365.

Microsoft 365

The scan creates nine types: the tenant itself, the four services Microsoft Teams, OneDrive, SharePoint Online and Exchange Online, and Entra ID with users, groups and contacts.
Entra ID User is the most extensive type in the family: it carries six groups because it draws together from four sources — the directory, licensing, sign-ins and Teams.

Microsoft Intune

The scan creates six types: the tenant itself, the device registered in Entra ID, and four device kinds — Intune Device (generic), Android Device, iPhone and iPad. Each device type carries system details and installed software.
Intune is the only module on this page that creates its own devices.

Microsoft Identity

A pure linking type: it connects the Windows SID of an account from the Windows (AD) scan with the Entra ID object ID from the Microsoft 365 scan — the same identity in both directories. No scan module creates it directly; it arises from matching both accounts and carries no view of its own.
If you scan both systems, every hybrid account exists twice in the inventory. Both accounts continue to exist separately and carry their own status — this type only records that they belong together, without merging them.
Credentials for both scan modules — the Entra ID app registration — are in the Scan Reference. How a user in Active Directory and in Entra ID connects is shown in the Relations tab. How devices are captured that neither of these managements knows about is described under Network and Devices.