> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Cloud and Identity

> Microsoft 365, Entra ID and Intune – which types these scan modules create and how their detail pages are structured.

Two scan modules capture Microsoft's cloud environment, plus a linking type
with no scan of its own. Both scan modules need an app registration for
access — see [Inventorying Microsoft 365](/docs/en/scan/microsoft-365).

## Microsoft 365

The scan creates nine types: the tenant itself, the four services *Microsoft
Teams*, *OneDrive*, *SharePoint Online* and *Exchange Online*, and Entra ID
with users, groups and contacts.

| Type | Group | Areas |
| - | - | - |
| Microsoft 365 | Users / Billing | Active Users, Contacts, Licenses |
| Entra ID | Resources | Users, Groups, Contacts, Devices, Enterprise Applications, Deleted Objects |
| Entra ID | Authorization Assignment | Directory Roles, Conditional Access |
| Entra ID User | Basic Information | Organization, Proxy Addresses, Directory Roles |
| Entra ID User | Microsoft Entra ID | Authentication Methods, Group Memberships, App Role Assignments, Last Sign-Ins |
| Teams / OneDrive / SharePoint / Exchange | Basic Information | own areas per service (teams, storage, sites, mailboxes) |

<Note>
  *Entra ID User* is the most extensive type in the family: it carries six
  groups because it draws together from four sources — the directory,
  licensing, sign-ins and Teams.
</Note>

## Microsoft Intune

The scan creates six types: the tenant itself, the device registered in
Entra ID, and four device kinds — *Intune Device* (generic), *Android
Device*, *iPhone* and *iPad*. Each device type carries system details and
installed software.

<Note>
  Intune is the only module on this page that creates its own devices.
</Note>

## Microsoft Identity

A pure linking type: it connects the Windows SID of an account from the
*Windows (AD)* scan with the Entra ID object ID from the *Microsoft 365* scan
— the same identity in both directories. No scan module creates it directly;
it arises from matching both accounts and carries no view of its own.

<Note>
  If you scan both systems, every hybrid account exists twice in the
  inventory. Both accounts continue to exist separately and carry their own
  status — this type only records that they belong together, without merging
  them.
</Note>

## Related

Credentials for both scan modules — the Entra ID app registration — are in
the [Scan Reference](/docs/en/scan/reference). How a user in Active Directory and
in Entra ID connects is shown in the
[Relations](/docs/en/assets/relations) tab. How devices are captured that neither
of these managements knows about is described under
[Network and Devices](/docs/en/assets/network-devices).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.